<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>spylogic.net &#187; Tom</title>
	<atom:link href="http://www.spylogic.net/author/tom/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.spylogic.net</link>
	<description></description>
	<lastBuildDate>Tue, 04 Oct 2011 20:43:32 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Don&#8217;t Drop the SOAP: Real World Web Service Testing for Web Hackers Presentation</title>
		<link>http://www.spylogic.net/2011/08/dont-drop-the-soap-real-world-web-service-testing-for-web-hackers-presentation/</link>
		<comments>http://www.spylogic.net/2011/08/dont-drop-the-soap-real-world-web-service-testing-for-web-hackers-presentation/#comments</comments>
		<pubDate>Wed, 31 Aug 2011 15:48:30 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Web Services]]></category>
		<category><![CDATA[blackhat]]></category>
		<category><![CDATA[defcon]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[owasp]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[pentesting]]></category>
		<category><![CDATA[securestate]]></category>
		<category><![CDATA[soap]]></category>
		<category><![CDATA[web-services]]></category>
		<category><![CDATA[whitepaper]]></category>

		<guid isPermaLink="false">http://www.spylogic.net/?p=564</guid>
		<description><![CDATA[Sorry for the long delay on posting the slides from the presentation that myself, Josh Abraham and Kevin Johnson did at Black Hat USA and DEF CON 19.  I&#8217;ve uploaded the slides from DEF CON to SlideShare (you can also download a copy there as well) and below are the links to the tools and [...]]]></description>
			<content:encoded><![CDATA[<p>Sorry for the long delay on posting the slides from the presentation that myself, Josh Abraham and Kevin Johnson did at Black Hat USA and DEF CON 19.  I&#8217;ve uploaded the slides from DEF CON to <a href="http://www.slideshare.net/agent0x0/dont-drop-the-soap-real-world-web-service-testing-for-web-hackers">SlideShare</a> (you can also download a copy there as well) and below are the links to the tools and white paper.  I&#8217;m currently in the process of working with OWASP to get the testing methodology put into the next version of the OWASP testing guide (v4).  If you have any comments or bug reports for the tools and vulnerable web services please let <a href="http://twitter.com/jabra">Josh</a> and <a href="http://twitter.com/secureideas">Kevin</a> know, they would appreciate it!</p>
<p><a href="http://www.spylogic.net/wp-content/uploads/2011/08/Dont-Drop-the-SOAP-Whitepaper.pdf">Download the white paper.</a>  <a href="http://spl0it.org/msf_web_services.tar.bz2">Download Josh&#8217;s Metasploit modules.</a>  <a href="http://dvws.secureideas.net/">Download Kevin&#8217;s vulnerable web services.</a></p>
<div id="__ss_9084302" style="width: 425px;">
<p><strong style="display: block; margin: 12px 0 4px;"><a title="Don't Drop The SOAP: Real World Web Service Testing for Web Hackers " href="http://www.slideshare.net/agent0x0/dont-drop-the-soap-real-world-web-service-testing-for-web-hackers" target="_blank">Don&#8217;t Drop the SOAP: Real World Web Service Testing for Web Hackers </a></strong> <object id="__sse9084302" width="425" height="355" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=defcondontdropthesoappresentation-defcon-110831100544-phpapp02&amp;stripped_title=dont-drop-the-soap-real-world-web-service-testing-for-web-hackers&amp;userName=agent0x0" /><param name="allowscriptaccess" value="always" /><param name="allowfullscreen" value="true" /><embed id="__sse9084302" width="425" height="355" type="application/x-shockwave-flash" src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=defcondontdropthesoappresentation-defcon-110831100544-phpapp02&amp;stripped_title=dont-drop-the-soap-real-world-web-service-testing-for-web-hackers&amp;userName=agent0x0" allowFullScreen="true" allowScriptAccess="always" allowscriptaccess="always" allowfullscreen="true" /> </object></p>
<div style="padding: 5px 0 12px;">View more <a href="http://www.slideshare.net/" target="_blank">presentations</a> from <a href="http://www.slideshare.net/agent0x0" target="_blank">agent0x0</a></div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2011/08/dont-drop-the-soap-real-world-web-service-testing-for-web-hackers-presentation/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Attacking and Defending Apple iOS Devices Presentation</title>
		<link>http://www.spylogic.net/2011/05/attacking-and-defending-apple-ios-devices-presentation/</link>
		<comments>http://www.spylogic.net/2011/05/attacking-and-defending-apple-ios-devices-presentation/#comments</comments>
		<pubDate>Fri, 20 May 2011 17:11:21 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[enterprise]]></category>
		<category><![CDATA[ios]]></category>
		<category><![CDATA[issa]]></category>
		<category><![CDATA[jailbreaking]]></category>
		<category><![CDATA[mobile]]></category>
		<category><![CDATA[pentest]]></category>

		<guid isPermaLink="false">http://www.spylogic.net/?p=550</guid>
		<description><![CDATA[Last week I spoke at the Central Ohio ISSA Conference about Attacking and Defending Apple IOS Devices.  This talk was based on information gathered from several of the mobile pentests that I conducted at SecureState.  I&#8217;ll be working on more research that will be going into an white paper that I will hopefully be releasing [...]]]></description>
			<content:encoded><![CDATA[<p>Last week I spoke at the <a href="http://infosecsummit.org/index.html">Central Ohio ISSA Conference</a> about Attacking and Defending Apple IOS Devices.  This talk was based on information gathered from several of the mobile pentests that I conducted at SecureState.  I&#8217;ll be working on more research that will be going into an white paper that I will hopefully be releasing in the next few months.  You can find my slides on SlideShare below and <a href="http://www.irongeek.com/i.php?page=videos/attacking-and-defending-apple-ios-devices-tom-eston">watch the video graciously recorded by Iron Geek</a>.</p>
<p><strong>UPDATE (5/27):</strong> I found a <a href="https://github.com/ptoomey3/Keychain-Dumper">very nice script by Patrick Toomey</a> which can dump the contents of the keychain on Jailbroken iOS devices.  More details about how the script runs can be found <a href="http://labs.neohapsis.com/2011/02/28/researchers-steal-iphone-passwords-in-6-minutes-true-but-not-the-whole-story/">in this blog post</a>.  Note that the type of information you get back depends if the passcode is enabled or not.  You will get more keychain entries back if the passcode is not enabled.  I had mentioned in my presentation that I hadn&#8217;t found a script to do this yet&#8230;well here it is. <img src='http://www.spylogic.net/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<div id="__ss_8042641" style="width: 425px;"><strong style="display: block; margin: 12px 0 4px;"><a title="Attacking and Defending Apple iOS Devices" href="http://www.slideshare.net/agent0x0/attacking-and-defending-apple-ios-devices">Attacking and Defending Apple iOS Devices</a></strong> <object id="__sse8042641" width="425" height="355"><param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=attackinganddefendingiosdevices-final-110520112732-phpapp01&amp;stripped_title=attacking-and-defending-apple-ios-devices&amp;userName=agent0x0" /><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><embed type="application/x-shockwave-flash" width="425" height="355" src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=attackinganddefendingiosdevices-final-110520112732-phpapp01&amp;stripped_title=attacking-and-defending-apple-ios-devices&amp;userName=agent0x0" name="__sse8042641" allowscriptaccess="always" allowfullscreen="true"></embed></object>&nbsp;</p>
<div style="padding: 5px 0 12px;">View more <a href="http://www.slideshare.net/">presentations</a> from <a href="http://www.slideshare.net/agent0x0">agent0x0</a></div>
</div>
<p><script src="http://b.scorecardresearch.com/beacon.js?c1=7&amp;c2=7400849&amp;c3=1&amp;c4=&amp;c5=&amp;c6="></script><br />
 <script src="http://b.scorecardresearch.com/beacon.js?c1=7&amp;c2=7400849&amp;c3=1&amp;c4=&amp;c5=&amp;c6="></script></p>
<p><script src="http://b.scorecardresearch.com/beacon.js?c1=7&amp;c2=7400849&amp;c3=1&amp;c4=&amp;c5=&amp;c6="></script></p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2011/05/attacking-and-defending-apple-ios-devices-presentation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Social Zombies at #NOTACON This Weekend</title>
		<link>http://www.spylogic.net/2011/04/social-zombies-at-notacon-this-weekend/</link>
		<comments>http://www.spylogic.net/2011/04/social-zombies-at-notacon-this-weekend/#comments</comments>
		<pubDate>Fri, 15 Apr 2011 19:32:40 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[geolocation]]></category>
		<category><![CDATA[notacon]]></category>
		<category><![CDATA[Privacy on the Internetz]]></category>
		<category><![CDATA[qrcodes]]></category>
		<category><![CDATA[socialnetworking]]></category>

		<guid isPermaLink="false">http://www.spylogic.net/?p=542</guid>
		<description><![CDATA[Kevin Johnson and I will be speaking at Notacon this Saturday at 1pm! We are giving our third and final Social Zombies talk on hacking Geolocation and social networks: Social Zombies Gone Wild: Totally Exposed and Uncensored.  Lot&#8217;s of fun is planned!]]></description>
			<content:encoded><![CDATA[<p>Kevin Johnson and I will be speaking at <a href="http://notacon.org">Notacon</a> this Saturday at 1pm! We are giving our third and final Social Zombies talk on hacking Geolocation and social networks: <a href="http://notacon.org/speakers.php#Zombies">Social Zombies Gone Wild: Totally Exposed and Uncensored</a>.  Lot&#8217;s of fun is planned!</p>
<p><img class="alignnone size-full wp-image-543" title="check_out_this_qr_code" src="http://www.spylogic.net/wp-content/uploads/2011/04/qr.png" alt="" width="420" height="420" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2011/04/social-zombies-at-notacon-this-weekend/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Two New Social Media Security White Papers Released</title>
		<link>http://www.spylogic.net/2010/10/two-new-social-media-security-white-papers-released/</link>
		<comments>http://www.spylogic.net/2010/10/two-new-social-media-security-white-papers-released/#comments</comments>
		<pubDate>Thu, 14 Oct 2010 03:53:18 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[informationgathering]]></category>
		<category><![CDATA[myspace]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[socialmedia]]></category>
		<category><![CDATA[socialnetworking]]></category>
		<category><![CDATA[socnetsec]]></category>
		<category><![CDATA[speaking]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[wordlists]]></category>

		<guid isPermaLink="false">http://www.spylogic.net/?p=527</guid>
		<description><![CDATA[My employer (SecureState) has released two white papers as part of our Social Media Security Awareness Month.  You can also download some cool wallpaper for this month created by Rob our graphic designer (see the picture on the right).  :-) First is some research several of my colleagues and I worked on.  The paper is titled: [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.spylogic.net/wp-content/uploads/2010/10/SecureStateSocialMedia_1024x768.jpg"><img class="size-thumbnail wp-image-528 alignright" title="SecureStateSocialMedia_1024x768" src="http://www.spylogic.net/wp-content/uploads/2010/10/SecureStateSocialMedia_1024x768-150x150.jpg" alt="" width="150" height="150" /></a>My employer (SecureState) has released two white papers as part of our <a href="http://www.securestate.com/Services/Profiling--Penetration/Offensive/Pages/SocialScan.aspx">Social Media Security Awareness Month</a>.  You can also <a href="http://www.securestate.com/MediaCenter/Pages/Wallpapers.aspx">download</a> some cool wallpaper for this month created by Rob our graphic designer (see the picture on the right).  :-)</p>
<p>First is some research several of my colleagues and I worked on.  The paper is titled: <strong>&#8220;Profiling User Passwords on Social Networks&#8221;</strong>.  The paper discusses the password problem that we all know and love as well as how you can determine passwords by what individuals post on their profiles.  We dive into tools from <a href="http://www.digininja.org/">Robin Wood</a>, Mark Baggett and others that can be used to pull keywords from profiles and other sources to create wordlists.  These wordlists can be used for brute force attacks on user accounts.  Next, we look at password complexity of several popular social networks with some research around brute force controls that some of the social networks have implemented, or in some cases haven&#8217;t.  Lastly, we discuss some things that users of social networks can do when choosing passwords.  <a href="http://www.securestate.com/Downloadables/Documents/Whitepapers/Profiling_User_Passwords_on_Social_Networks.pdf">You can download my paper here</a>.</p>
<p>The other paper released is titled: <strong>&#8220;Security Gaps in Social Media Websites for Children Open Door to Attackers Aiming To Prey On Children&#8221;</strong> by my colleague Scott White.  In his paper he looks at the security of social media websites specifically designed for children.  This is some very detailed research and sheds some light on how predators are using these sites to target children as well as some issues that are unique to these types of social media websites.  <a href="http://www.securestate.com/Downloadables/Documents/Whitepapers/Security_Gaps_in_Social_Media_Websites_for_Children.pdf">You can download Scott&#8217;s paper here</a>.</p>
<p>Speaking of social media&#8230;I&#8217;ll be presenting &#8220;Social Impact: Risks and Rewards of Social Media&#8221; at the <a href="https://www.informationsecuritysummit.org/">Information Security Summit </a>this Friday at 10am.  I&#8217;ll have the slide deck posted shortly after the conference.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2010/10/two-new-social-media-security-white-papers-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hacking Your Location With Facebook Places</title>
		<link>http://www.spylogic.net/2010/08/hacking-your-location-with-facebook-places/</link>
		<comments>http://www.spylogic.net/2010/08/hacking-your-location-with-facebook-places/#comments</comments>
		<pubDate>Tue, 24 Aug 2010 17:41:00 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[geolocation]]></category>
		<category><![CDATA[socialmedia]]></category>
		<category><![CDATA[socialnetworking]]></category>
		<category><![CDATA[socnetsec]]></category>
		<category><![CDATA[zombies]]></category>

		<guid isPermaLink="false">http://www.spylogic.net/?p=520</guid>
		<description><![CDATA[I just published a post over on the SecureState blog about how to hack your location using Facebook Places.  The post brings up some interesting questions about how social networks are going to have a problem with fake location check-in&#8217;s. In the meantime, it&#8217;s a way to have fun with your friends&#8230;:-)]]></description>
			<content:encoded><![CDATA[<p>I just published a post over on the SecureState blog about how to <a href="http://securestate.blogspot.com/2010/08/hacking-your-location-with-facebook.html">hack your location using Facebook Places</a>.  The post brings up some interesting questions about how social networks are going to have a problem with fake location check-in&#8217;s. In the meantime, it&#8217;s a way to have fun with your friends&#8230;:-)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2010/08/hacking-your-location-with-facebook-places/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Overview and Review of Maltego 3</title>
		<link>http://www.spylogic.net/2010/06/overview-and-review-of-maltego-3/</link>
		<comments>http://www.spylogic.net/2010/06/overview-and-review-of-maltego-3/#comments</comments>
		<pubDate>Wed, 30 Jun 2010 03:18:50 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[informationgathering]]></category>
		<category><![CDATA[maltego]]></category>
		<category><![CDATA[paterva]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.spylogic.net/?p=500</guid>
		<description><![CDATA[A few weeks ago the fine folks over at Paterva released the next version of their information gathering tool, Maltego 3.  Ever since day one of the product I&#8217;ve been a huge fan and have used it in multiple penetration tests and various reconnaissance activities.  I know I&#8217;m not alone as many of you in [...]]]></description>
			<content:encoded><![CDATA[<p>A few weeks ago the fine folks over at Paterva released the next version of their information gathering tool, <a href="http://www.paterva.com/web5/">Maltego 3</a>.  Ever since day one of the product I&#8217;ve been a huge fan and have used it in multiple penetration tests and various reconnaissance activities.  I know I&#8217;m not alone as many of you in the security community use Maltego and also see the value that it brings.  Maltego 3 is no different.  However: it&#8217;s faster, more feature rich and has a damn sexy UI.  I won&#8217;t go into a ton of detail in this post but I want to highlight some of the awesome changes that I&#8217;ve noticed.</p>
<p><strong>Setup and UI</strong><br />
The first thing you will notice is the startup wizard (Figure 1) that walks you though setting up your license and updating the TAS to download new transforms.  The wizard is a welcome addition especially for new users.</p>
<p><a href="http://www.spylogic.net/wp-content/uploads/2010/06/update_wizard.jpg"><img class="alignnone size-medium wp-image-501" title="update_wizard" src="http://www.spylogic.net/wp-content/uploads/2010/06/update_wizard-300x215.jpg" alt="" width="300" height="215" /></a><em><br />
Figure 1. The Maltego 3 startup wizard.</em></p>
<p>You will notice that the transform manager itself has also gotten a face lift with a column showing you if a disclaimer is required or not (Figure 2).</p>
<p><a href="http://www.spylogic.net/wp-content/uploads/2010/06/transforms_disclaimer.jpg"><img class="alignnone size-medium wp-image-502" title="transforms_disclaimer" src="http://www.spylogic.net/wp-content/uploads/2010/06/transforms_disclaimer-300x214.jpg" alt="" width="300" height="214" /></a><br />
<em>Figure 2. The transform manager now shows you which transforms have a disclaimer or not.</em></p>
<p>Another noticeable change is the UI.  It&#8217;s sleek and sexy.  I also like how the main menu is grouped into two tabs: Investigate and Manage (Figures 3 and 4).  The Paterva team did a great job grouping items so its easy to select what you need.</p>
<p><a href="http://www.spylogic.net/wp-content/uploads/2010/06/manage_tab.jpg"><img class="alignnone size-medium wp-image-503" title="manage_tab" src="http://www.spylogic.net/wp-content/uploads/2010/06/manage_tab-300x61.jpg" alt="" width="300" height="61" /></a></p>
<p><em>Figure 3. Menu items are grouped into two tabs now.  Items are much easier to select.  This is the &#8220;Manage&#8221; tab.</em></p>
<p><em><a href="http://www.spylogic.net/wp-content/uploads/2010/06/investigate_tab.jpg"><img class="alignnone size-medium wp-image-506" title="investigate_tab" src="http://www.spylogic.net/wp-content/uploads/2010/06/investigate_tab-300x52.jpg" alt="" width="300" height="52" /></a></em></p>
<p><em>Figure 4. The &#8220;Investigate&#8221; tab.<br />
</em></p>
<p>Back to the main UI.  Adding objects is similar to before but it&#8217;s faster and more responsive.  Figure 5 is a screen shot of the entire UI.</p>
<p><a href="http://www.spylogic.net/wp-content/uploads/2010/06/maltego_client_twitter.jpg"><img class="alignnone size-medium wp-image-504" title="maltego_client_twitter" src="http://www.spylogic.net/wp-content/uploads/2010/06/maltego_client_twitter-300x180.jpg" alt="" width="300" height="180" /></a></p>
<p><em>Figure 5. Simple Twitter search using the new Maltego 3 UI.</em></p>
<p>Entities connected to each other are easier to view.  When arrows connect to entities they move around other objects. (Figure 6).</p>
<p><a href="http://www.spylogic.net/wp-content/uploads/2010/06/maltego_client1.jpg"><img class="alignnone size-medium wp-image-505" title="maltego_client1" src="http://www.spylogic.net/wp-content/uploads/2010/06/maltego_client1-300x180.jpg" alt="" width="300" height="180" /></a></p>
<p><em>Figure 6. Maltego 3 offers some nice UI improvements when moving entities around the screen.</em></p>
<p><strong>Site Links and Entity Listings</strong><br />
Two other items I want to mention are some improvements on how links to and from a site are shown and the entity listing feature.  The site links transform rocks.  You can now see incoming and outgoing links to a website entity.</p>
<p><a href="http://www.spylogic.net/wp-content/uploads/2010/06/maltego_links.jpg"><img class="alignnone size-medium wp-image-508" title="maltego_links" src="http://www.spylogic.net/wp-content/uploads/2010/06/maltego_links-300x140.jpg" alt="" width="300" height="140" /></a></p>
<p><em>Figure 7. Links in and out of a website are easy to obtain in Maltego 3.</em></p>
<p>Lastly, I found the entity listing view most helpful.  This allows you to search and sort all the entities in your Maltego UI into a nice easy to view list (Figure 8).  Also, the dynamic view is pretty sweet as well.</p>
<p><a href="http://www.spylogic.net/wp-content/uploads/2010/06/maltego_entity_list.jpg"><img class="alignnone size-medium wp-image-509" title="maltego_entity_list" src="http://www.spylogic.net/wp-content/uploads/2010/06/maltego_entity_list-300x180.jpg" alt="" width="300" height="180" /></a></p>
<p><em>Figure 8.  The entity list view provides a great way to search for things within the UI.</em></p>
<p>You can get the commercial version of Maltego now and the Community Edition is right around the corner.  Version 2 users can also use your same license key with Maltego 3.  Win!  Also, if your hesitant about buying a commercial product like this, don&#8217;t be.  Maltego is quite affordable for all the power you get and well worth it.  Reconnaissance is fun again! <img src='http://www.spylogic.net/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />   <a href="http://www.paterva.com/web5/client/overview.php">More information about Maltego 3 is here.</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2010/06/overview-and-review-of-maltego-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Interesting New Twitter Phish Can Lead to Bad Places</title>
		<link>http://www.spylogic.net/2010/06/interesting-new-twitter-phish-can-lead-to-bad-places/</link>
		<comments>http://www.spylogic.net/2010/06/interesting-new-twitter-phish-can-lead-to-bad-places/#comments</comments>
		<pubDate>Thu, 24 Jun 2010 12:00:30 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[socnetsec]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.spylogic.net/?p=468</guid>
		<description><![CDATA[I&#8217;ve had several fake emails that initially look like they come from Twitter in my email recently.  I didn&#8217;t think anything of it until several of my friends forwarded me the same type of emails.  This suggests two things.  One, that these emails are starting to hit a larger audience.  Or two, they are targeting [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve had several fake emails that initially look like they come from Twitter in my email recently.  I didn&#8217;t think anything of it until several of my friends forwarded me the same type of emails.  This suggests two things.  One, that these emails are starting to hit a larger audience.  Or two, they are targeting just my friends and I which is totally possible. <img src='http://www.spylogic.net/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  Anyway, here is a quick bit of analysis of one of these emails.  I found some interesting things when I investigated the website linked in the fake email.  The link in this particular could have done more damage if it wasn&#8217;t for some crappy attacker code.  Read on!</p>
<p><strong>The Email</strong><br />
The following screen shot shows you what the email looks like.  It seems to come from Twitter but you will notice that there are some interesting clues that tell you this isn&#8217;t real.  First, the Twitter account mentioned is just the first part of the email address this was sent to.  This may or may not be your Twitter ID.  Second, check out the &#8220;Britney Spears home video feedback&#8221; subject line and &#8220;Antidepressants for your bed vigor&#8221; bold red in the message body.  Yep.  All the signs that this isn&#8217;t from Twitter.  Ok, nothing to see here right?</p>
<p><a href="http://www.spylogic.net/wp-content/uploads/2010/06/email_phish.jpg"><img class="alignnone size-medium wp-image-471" title="email_phish" src="http://www.spylogic.net/wp-content/uploads/2010/06/email_phish-300x193.jpg" alt="" width="300" height="193" /></a></p>
<p><strong>The Link</strong><br />
When you look at the source of the email, the link actually goes to &#8220;hxxp://89.161.148.201/cekfcq.html&#8221;. If you do click on this link several things happen:</p>
<p>An HTML page is loaded which redirects you to a shady Russian software site.  This site (software-oemdigital.ru) has a ton of phisy looking domains that were assigned to it since 6/11/2010.  The HTML file also loads a script which runs a PHP file on another server.  Let&#8217;s take a look at the response:</p>
<blockquote><p>HTTP/1.0 200 OK<br />
Connection: close<br />
Content-Length: 250<br />
Content-Type: text/html<br />
Date: Wed, 23 Jun 2010 15:09:53 GMT<br />
Last-Modified: Wed, 23 Jun 2010 08:30:01 GMT<br />
Server: IdeaWebServer/v0.70</p>
<p>&lt;!DOCTYPE HTML PUBLIC &#8220;-//W3C//DTD HTML 4.01 Transitional//EN&#8221;&gt;</p>
<p>&lt;META HTTP-EQUIV=&#8221;refresh&#8221; CONTENT=&#8221;0;URL=hxxp://software-oemdigital.ru&#8221;&gt;<br />
&lt;title&gt;&lt;/title&gt;</p>
<p>&lt;html&gt;&lt;head&gt;<br />
&lt;/head&gt;&lt;/html&gt;&lt;script src=hxxp://eurolisting.net/Cgi-bin/markprint.php &gt;&lt;/script&gt;</p></blockquote>
<p>The Russian software site loads as normal but something else is going on in the background from eurolisting.net and that PHP file.  Here is the response:</p>
<blockquote><p>HTTP/1.1 200 OK<br />
Connection: close<br />
Date: Wed, 23 Jun 2010 17:46:54 GMT<br />
Server: Microsoft-IIS/6.0<br />
X-Powered-By: ASP.NET<br />
X-Powered-By: PHP/5.2.6<br />
Set-Cookie: PHPSESSID=1287414902; path=/<br />
Expires: Thu, 19 Nov 1981 08:52:00 GMT<br />
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0<br />
Pragma: no-cache<br />
Content-Type: application/javascript</p>
<p>// &lt;script&gt;<br />
function cxx(wcH){return wcH.replace(/%/g,&#8221;).replace(/['ow:Y]/g,fUp)}<br />
cPH7j=&#8217;d:6fcY75meY6et.Y77rio74w65(Y22o3cdiv stylew3d:5cY22pw6fsitio6fnY3aaw62so6fl:75o74Y65o3b lefto3a:2d1000pxY3bw20tY6fp:3aw2d10w300pxw3bo5cw22:3ew22Y29w3b:66unctiY6fn :6973(a)o7bdY6fcu:6deY6et.w77rw69te(:22:3cifrao6d:65w20srcw3do5co22httw70Y3ao2f &lt;SNIP&gt;</p></blockquote>
<p>All of the stuff following the script tag is obfuscated JavaScript.  I cut most of it out as it is quite lengthy.  Running this through <a href="http://jsunpack.jeek.org">jsunpack</a> (a JavaScript unpacker) the script tries to load several things including some VBScript that seems to check for system properties, if you are running Firefox and if you have Java and/or Flash enabled as well as what seems to be a check for Adobe Reader plug-ins.  You can check out the script and the unpacked version over at the <a href="http://jsunpack.jeek.org/dec/go?report=cbb10579a66ac694ab7265538a98582d6f1ff709">jsunpack site</a>.</p>
<p>Now this is where it gets interesting.  In Internet Explorer the PHP file seems to generate a request to a URI that doesn&#8217;t exist: hxxp://89.161.148.201/zzz/ttt/ad3740b4.class, it 404&#8242;s.  You can also see this in the Wireshark capture below:</p>
<p><a href="http://www.spylogic.net/wp-content/uploads/2010/06/wireshark.jpg"><img class="alignnone size-medium wp-image-472" title="wireshark" src="http://www.spylogic.net/wp-content/uploads/2010/06/wireshark-300x71.jpg" alt="" width="300" height="71" /></a></p>
<p>In Firefox it&#8217;s a different story.  The Russian software site still loads and something else attempts to get requested:</p>
<p>hxxp://wiki.insuranceplanningaz.com/main.php?h=89.161.148.201&amp;i=JcmridQaq/ykgRj4UMpOy5Ec&amp;e=4</p>
<p>This site will lead to some fun &#8220;fake AV&#8221; which prompts you to download a &#8220;setup.exe&#8221; file.</p>
<p><a href="http://www.spylogic.net/wp-content/uploads/2010/06/fake_av4.jpg"><img class="alignnone size-medium wp-image-493" title="fake_av4" src="http://www.spylogic.net/wp-content/uploads/2010/06/fake_av4-300x172.jpg" alt="" width="300" height="172" /></a></p>
<p>You probably don&#8217;t want to run that file.  The good news is that if you have the latest version of Firefox it will note this as a reported web forgery and tries to prevent you from going there.  One problem I see is that if you are running an older version of Firefox you might not get this notification.  I haven&#8217;t tested this with other browsers but your results may vary.</p>
<p>What does this all mean?  Well of course don&#8217;t click on shady emails like this.  You know better right?  Also, don&#8217;t think that because you use Firefox you are safe from attacks like these!  Attackers are catching on and I would suspect we will see more attacks targeting multiple browsers besides IE.  Wait, too late isn&#8217;t it?  Special thanks to <a href="http://securityblahblah.blogspot.com/">Greg</a> and <a href="http://secshoggoth.blogspot.com">Tyler</a> for providing intel about these domains and some of the analysis.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2010/06/interesting-new-twitter-phish-can-lead-to-bad-places/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Story of a Security Guy at the Marketing Conference</title>
		<link>http://www.spylogic.net/2010/06/the-story-of-a-security-guy-at-the-marketing-conference/</link>
		<comments>http://www.spylogic.net/2010/06/the-story-of-a-security-guy-at-the-marketing-conference/#comments</comments>
		<pubDate>Sun, 13 Jun 2010 03:57:14 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[General Security]]></category>
		<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[HR]]></category>
		<category><![CDATA[marketing]]></category>
		<category><![CDATA[policies]]></category>
		<category><![CDATA[PR]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[socialmedia]]></category>
		<category><![CDATA[socialnetworking]]></category>

		<guid isPermaLink="false">http://www.spylogic.net/?p=464</guid>
		<description><![CDATA[Last week I was asked by some of my social media acquaintances to be a panelist on a end of the day keynote at the Online Marketing Summit (OMS) held in Cleveland, OH.  The first thing you are probably wondering is &#8220;What the hell is a security guy doing at a marketing conference&#8221;?  Let me [...]]]></description>
			<content:encoded><![CDATA[<p>Last week I was asked by some of my social media acquaintances to be a panelist on a end of the day keynote at the <a href="http://www.onlinemarketingsummit.com/regional/cleveland/">Online Marketing Summit (OMS) </a>held in Cleveland, OH.  The first thing you are probably wondering is &#8220;What the hell is a security guy doing at a marketing conference&#8221;?  Let me explain.  This isn&#8217;t the first time I have done something like this and it probably won&#8217;t be the last.  Read on.</p>
<p>In many companies the marketing, public relations, HR and other &#8220;business&#8221; functions really don&#8217;t want anything to do with security.  It&#8217;s true.  We always get in the way by stopping money making and/or great marketing ideas with phrases like &#8220;If you do that&#8230;the hax0rs are going to pwn us!&#8221; or &#8220;No you can&#8217;t, that&#8217;s against our security policy.  Go away now.&#8221;  Unfortunately, all it takes is one bad experience from the &#8220;security people&#8221; and they won&#8217;t want to work with you ever again.  I&#8217;ve seen it happen many times and I&#8217;ve even been &#8220;that evil security guy&#8221; at various times in my career.</p>
<p>It&#8217;s because of this bull headed attitude that these departments start finding ways around your policies, procedures, website blocking and more.  Why? Because security people are increasingly impossible to deal with.  Too much red tape, policies, rules and most of all&#8230;lack of communication.  That&#8217;s right, I said it.  Lack of <em>good</em> communication.  When was the last time you talked to these people in your company?  When was the last time you offered to help them with a compromise or solution rather then saying no?  This might be a shock to some of you but these are the people helping make the business money.  All of us in security are just an extra expense to the business.  Don&#8217;t make our jobs harder!  Here are three steps to help communicate to these people better:</p>
<p><strong>1. Get out of your shell</strong><br />
We love to hang out and network at security conferences and user groups.  It makes sense because we are comfortable around our own people.  However, take a step back and think about what the &#8220;business needs&#8221; for a minute.  You are there to help the business succeed.  So go out and help them!  One way to do this is to attend a marketing conference.  Seriously.  You get to meet and talk to people that want to help the business make money and know how to do it.  You also get to learn what the business wants.  This will get you thinking about how you as the &#8220;security person&#8221; can help make that happen while keeping the business and its information safe.</p>
<p><strong>2. Learn something new</strong><br />
What does marketing have to do with security?  All kinds of things!  SEO, blogging, social networking, social media, brand reputation, monitoring and more.  These are hot topics right now and there are serious security and privacy issues to be concidered.  You need to be involved!  The best way to do this is to attend their conferences, read their blogs and communicate.  One good way to get involved is to look for a local social media club in your area.  <a href="http://clevelandsmc.ning.com/">We have a great one in Cleveland</a> and there are others in cities all over the US and probably the world.  Attend, learn and network.  It can only benefit you and your company.  Same goes if you are a consultant.  Meeting marketing people is a great way to get new business because they usually have a direct line to upper management at a company.  They will also be so impressed that a security person actually took the time to show up to a marketing conference&#8230;they might call upper management for you. <img src='http://www.spylogic.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><strong>3. Teach and Educate</strong><br />
We have all &#8220;beaten the horse to death&#8221; regarding security awareness.  Many in security say it doesn&#8217;t work and is a hopeless battle.  While there is no patch for human stupidity, you still need to make an effort.  If anything, by you as the &#8220;security person&#8221; showing up at the marketing departments monthly meeting it shows that security wants to be involved with what they are doing.  This alone says volumes!  Especially to management of those groups.  Get out there and explain why you have certain policies, how the security team functions or better yet&#8230;how you can help them market the business and do it securely.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2010/06/the-story-of-a-security-guy-at-the-marketing-conference/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Facebook Privacy &amp; Security Guide Updated to v2.2</title>
		<link>http://www.spylogic.net/2010/06/facebook-privacy-security-guide-updated-to-v2-2/</link>
		<comments>http://www.spylogic.net/2010/06/facebook-privacy-security-guide-updated-to-v2-2/#comments</comments>
		<pubDate>Wed, 02 Jun 2010 04:05:41 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[Privacy on the Internetz]]></category>
		<category><![CDATA[socialmedia]]></category>
		<category><![CDATA[socialnetworking]]></category>
		<category><![CDATA[socnetsec]]></category>

		<guid isPermaLink="false">http://www.spylogic.net/?p=459</guid>
		<description><![CDATA[I have updated the Facebook Privacy &#38; Security Guide to version 2.2 over on SocialMediaSecurity.com.  If you&#8217;re not familiar with the guide it is an easy to use guide which helps you set the recommended privacy and security settings on your Facebook account.  It&#8217;s free, printable and meant to be shared. This update includes details [...]]]></description>
			<content:encoded><![CDATA[<p>I have updated the <a href="http://socialmediasecurity.com/security-guides/facebook/">Facebook Privacy &amp; Security Guide</a> to version 2.2 over on <a href="http://socialmediasecurity.com">SocialMediaSecurity.com</a>.  If you&#8217;re not familiar with the guide it is an easy to use guide which helps you set the recommended privacy and security settings on your Facebook account.  It&#8217;s free, printable and meant to be shared.</p>
<p>This update includes details on all the recent changes to Facebook&#8217;s privacy settings that went live May 26, 2010.  I have also included more information on &#8220;Instant Personalization&#8221;, removing yourself from &#8220;Platform&#8221;, and how your public information can be accessed via the Facebook Graph API.  Note that you may not have these settings enabled on your Facebook profile&#8230;yet.  They are slowly being rolled out to the Facebook user base and may take a few weeks.  Please share with friends, family and others!</p>
<p><a href="http://socialmediasecurity.com/downloads/Facebook_Privacy_and_Security_Guide.pdf">Download the latest version of the Facebook Privacy &amp; Security Guide here.</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2010/06/facebook-privacy-security-guide-updated-to-v2-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My Thoughts on the New Facebook Privacy Controls</title>
		<link>http://www.spylogic.net/2010/05/my-thoughts-on-the-new-facebook-privacy-controls/</link>
		<comments>http://www.spylogic.net/2010/05/my-thoughts-on-the-new-facebook-privacy-controls/#comments</comments>
		<pubDate>Thu, 27 May 2010 04:12:38 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Privacy on the Internetz]]></category>
		<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[socialmedia]]></category>
		<category><![CDATA[socnetsec]]></category>

		<guid isPermaLink="false">http://www.spylogic.net/?p=457</guid>
		<description><![CDATA[Ever since I started the Facebook Privacy &#38; Security Guide back in October 2008 I knew that Facebook&#8217;s privacy settings were confusing for the average user.  Many of my concerns back then centered around friends and family that had no idea there were even privacy settings to configure on Facebook.  It has also never been [...]]]></description>
			<content:encoded><![CDATA[<p>Ever since I started the <a href="http://socialmediasecurity.com/downloads/Facebook_Privacy_and_Security_Guide.pdf">Facebook Privacy &amp; Security Guide</a> back in October 2008 I knew that Facebook&#8217;s privacy settings were confusing for the average user.  Many of my concerns back then centered around friends and family that had no idea there were even privacy settings to configure on Facebook.  It has also never been in Facebook&#8217;s financial interest to *really* show you how to protect the information you post.  These are all reasons was why I started the guide and hopefully over the last few years it has helped spread some awareness on how to control the information you post a little better.  Working on the guide has been frustrating at times because Facebook would make settings more confusing, remove settings that were useful and then bring them back again in some other form.  In the latest versions of the guide I often wondered how I was going to fit all the settings and their explanations into a two-sided handout.  The handout format has always been important to me so it could be easily distributed. <img src='http://www.spylogic.net/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>Jumping forward to today we see yet <a href="http://blog.facebook.com/blog.php?post=391922327130">another iteration of these settings</a>.  I don&#8217;t have the settings on my Facebook account yet so I haven&#8217;t updated the guide but I have read some of the information already out there.  <a href="http://www.eff.org/deeplinks/2010/05/more-privacy-facebook-new-privacy-controls">The EFF has a good post up about the new settings</a>.  They even have a <a href="http://www.youtube.com/watch?v=TGkUA84ftYU">YouTube video</a> showing you the changes and their recommendations.  <a href="http://theharmonyguy.com/2010/05/26/facebook-backtracks-on-privacy-controls-and-public-information/">The other post you should read is one by theharmonyguy</a> who, as always, has very good analysis of these settings and Facebook overall.</p>
<p>My thoughts are pretty much along the same lines as the EFF and others.  However, I will say that no matter what changes Facebook makes to their privacy settings they *will* find ways to use your information to make money.  This is Mark Zuckerberg&#8217;s business model and that won&#8217;t change anytime soon.  I will leave you with a fantastic quote that I think sums up all the media drama leading up to these new privacy controls.  This is a quote from Bruce Schneier.  It&#8217;s from an article he did for <a href="http://www.forbes.com/2010/04/05/google-facebook-twitter-technology-security-10-privacy.html">Forbes</a> regarding statements that &#8220;Privacy is Dead&#8221;:</p>
<blockquote><p>&#8220;It&#8217;s just not true. People, including the younger generation, still care about privacy. Yes, they&#8217;re far more public on the Internet than their parents: writing personal details on Facebook, posting embarrassing photos on Flickr and having intimate conversations on Twitter. But they take steps to protect their privacy and vociferously complain when they feel it violated. They&#8217;re not technically sophisticated about privacy and make mistakes all the time, but that&#8217;s mostly the fault of companies and Web sites that try to manipulate them for financial gain.&#8221;</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2010/05/my-thoughts-on-the-new-facebook-privacy-controls/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Privacy and Security of Open Graph, Social Plugins and Instant Personalization on Facebook</title>
		<link>http://www.spylogic.net/2010/04/privacy-of-open-graph-social-plugins-and-instant-personalization-on-facebook/</link>
		<comments>http://www.spylogic.net/2010/04/privacy-of-open-graph-social-plugins-and-instant-personalization-on-facebook/#comments</comments>
		<pubDate>Fri, 23 Apr 2010 15:15:25 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[informationgathering]]></category>
		<category><![CDATA[opengraph]]></category>
		<category><![CDATA[Privacy on the Internetz]]></category>
		<category><![CDATA[socialmedia]]></category>
		<category><![CDATA[socialnetworking]]></category>
		<category><![CDATA[socialplugins]]></category>
		<category><![CDATA[socnetsec]]></category>

		<guid isPermaLink="false">http://www.spylogic.net/?p=444</guid>
		<description><![CDATA[As most major news organizations and blogs have covered the changes that Facebook has made from a high level, I wanted to focus this post specifically on Facebook&#8217;s &#8220;Open Graph&#8221;, &#8220;Social Plugins&#8221; and &#8220;Instant Personalization&#8221;.  In my opinion, these are three changes that will significantly impact the way you and your friends use Facebook.  As [...]]]></description>
			<content:encoded><![CDATA[<p>As most major news organizations and blogs have covered the changes that Facebook has made from a high level, I wanted to focus this post specifically on Facebook&#8217;s &#8220;Open Graph&#8221;, &#8220;Social Plugins&#8221; and &#8220;Instant Personalization&#8221;.  In my opinion, these are three changes that will significantly impact the way you and your friends use Facebook.  As I usually do, I will provide a point of view from the eyes of an attacker.  As we all know, its only a matter of time before these new features begin to be abused by attackers.</p>
<p><strong>Open Graph</strong><br />
The first significant change is Facebook&#8217;s &#8220;Open Graph&#8221;.  Open Graph is a significant departure from Facebook&#8217;s previous data connection strategy which used to be centered around Facebook Connect.  All of that is gone and replaced with Open Graph.  Open Graph basically allows partner websites and Facebook applications to share your public information and the public information of your friends with each other.  The other big change which is a departure from Facebook Connect is that developers can hold your data indefinitely.  The requirement was previously only for 24 hours (and we all know developers weren&#8217;t really holding to that anyway).</p>
<p>What&#8217;s also interesting is that Facebook has implemented an API called the <a href="http://developers.facebook.com/docs/api">Graph API</a>. The Graphs API is how developers can easily integrate their applications with this new stream of user data.  In fact, now you don&#8217;t even need a Facebook account to search the Open Graph.  For example, <a href="https://graph.facebook.com/search?q=facebook&amp;type=post">https://graph.facebook.com/search?q=facebook&amp;type=post</a> will show you 25 recent status updates.  Note that these status updates are set to Everyone and it seems that Facebook has put a limit on data you can retrieve with one query (this will change most likely or you can figure out ways around this).  Before you had to log in to Facebook to do a search or use some creative Google queries for this information.  This is good news for attackers, spammers and data miners.  Facebook has made publicly available information even easier to search for and in my opinion, is going to start competing with Google for personalized search results.  Stay tuned, Open Graph is going to be a huge area that I will be focusing my research on.  As a penetration tester, my job just got easier.  Thanks Facebook! <img src='http://www.spylogic.net/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p><strong>Social Plugins</strong><br />
Social plugins are small bits of code (the &#8220;Like&#8221; button for example) that you probably have been seeing all over the web.  What Facebook has done is added simple plugins that web site developers can easily integrate.  Also note that there are <a href="http://developers.facebook.com/plugins">many more plugins available besides the &#8220;Like&#8221; button</a>.  Simply run the wizard, fill in a few lines and you&#8217;re done.  Lets take the &#8220;Like&#8221; button as an example.  If you are signed into Facebook (or not) you will see the button just like you do on Mashable:</p>
<p><a href="http://www.spylogic.net/wp-content/uploads/2010/04/facebook_like_button.jpg"><img class="alignnone size-medium wp-image-446" title="facebook_like_button" src="http://www.spylogic.net/wp-content/uploads/2010/04/facebook_like_button-300x256.jpg" alt="" width="300" height="256" /></a></p>
<p>Clicking on the button while you are signed in to Facebook posts a notice to your news feed that you like Mashable.  The button also works when you are not logged into Facebook by prompting you to sign in.  This is similar to how Facebook Connect worked.  If you want to &#8220;unlike&#8221; the page, simply click the &#8220;Like&#8221; button again.  Already, <a href="http://arnab.org/blog/deceiving-users-facebook-button">someone has found a potential security problem with the &#8220;Like&#8221; button</a> that could possibly be abused by spammers.  Keep in mind that these social plugins are part of Facebook&#8217;s strategy to <span style="text-decoration: line-through;">take over the world</span> integrate their <a href="http://developers.facebook.com/docs/opengraph">Open Graph protocol</a>.  Once Open Graph starts to be more popular, you will see lots more attacks leveraging these new plugins.</p>
<p><strong>Instant Personalization</strong><br />
Lastly, we have &#8220;Instant Personalization&#8221;.  Instant Personalization is the feature in which Facebook has &#8220;pre-approved&#8221; third-party web sites to gain access to your public information just by visiting them.  There is very little information available currently on how Facebook approves third-party sites.  Once you allow these sites full authorization, they have the same access that any developer would have to your Facebook information.  For example, here is what it looks like when you surf to Yelp.  You will get a pretty blue bar that shows up at the top of your browser window:</p>
<p><a href="http://www.spylogic.net/wp-content/uploads/2010/04/facebook_yelp1.jpg"><img class="alignnone size-medium wp-image-448" title="facebook_yelp" src="http://www.spylogic.net/wp-content/uploads/2010/04/facebook_yelp1-300x38.jpg" alt="" width="300" height="38" /></a></p>
<p>You should notice that you have the option to &#8220;Learn More&#8221; or say &#8220;No, thanks&#8221;.  You will also notice how instantly, if any of your friends on Facebook are using Yelp you can see any of their activity just below the blue bar.</p>
<p>Now something interesting happens once you visit one of these pre-approved sites.  I noticed that a Facebook application (in this case Yelp) gets installed and allows it permissions to post.  You don&#8217;t have to even click &#8220;No thanks&#8221;, the application is already installed.  Pandora and Microsoft Docs work the same way.  In fact, when testing the Microsoft Docs personalization I noticed the Facebook application that gets installed sets its privacy permissions to EVERYONE and allows one-line posts on your behalf.  This means that anyone can see any activity that is posted by that application.  Keep in mind that these controls are all being closely looked at by  attackers and I suspect that we will see some hacks and/or abuse of this  new personalization system soon.</p>
<p><strong>Instant Personalization Privacy Settings</strong><br />
Facebook has put in a global &#8220;opt-out&#8221; check box in your privacy settings.  Of course in typical Facebook fashion they have buried this setting so it&#8217;s hard to find.  Ironically, just as I was writing this post Facebook changed the location of this setting.  So now you have to go down one more level by clicking an additional button to get to the setting (see the screen shot below).</p>
<p>There are some very important caveats about this setting.  First, <strong>this setting is enabled by default. </strong> Yes, that&#8217;s right.  If you have a Facebook account this setting is checked right now and you are opted in.  I had thought that Facebook would have learned from the <a href="http://en.wikipedia.org/wiki/Facebook_Beacon">Beacon fiasco</a> but it appears they haven&#8217;t.  Secondly, <strong>just because you &#8220;opt-out&#8221; doesn&#8217;t mean your information is safe</strong>.  Just like other Facebook applications if your <strong>FRIENDS</strong> use Yelp, Pandora or Microsoft Docs these sites can still get your public information or anything else you have made available to be shared with friends.  <strong>To completely opt-out you need to MANUALLY block each and every application (in this case Yelp, Pandora and MS Docs)</strong>.  It goes without saying, this is a huge pain and I look forward to the long list of complaints and privacy concerns regarding this psudo opt-out.  The other problem is that I have already seen posts by Facebook that they already have partner sites that they are going to announce soon.  What this means is that if you want to truly &#8220;opt-out&#8221; you need to keep up to date on all the new third-party partners with Facebook and manually block their applications.  This is a terrible control in my opinion.</p>
<p>So where are these settings?  Click on Account &#8211;&gt; Privacy Settings &#8211;&gt; Applications and Websites &#8211;&gt; Instant Personalization (Click the Edit Settings button).  In the screen shot below you can see the box that you need to uncheck.</p>
<p><a href="http://www.spylogic.net/wp-content/uploads/2010/04/facebook_personalization2.jpg"><img class="alignnone size-medium wp-image-450" title="facebook_personalization2" src="http://www.spylogic.net/wp-content/uploads/2010/04/facebook_personalization2-300x146.jpg" alt="" width="300" height="146" /></a></p>
<p><strong>UPDATE:</strong> <a href="http://twitter.com/ygjb">Yvan Boily</a> on Twitter had mentioned that you should also uncheck every box under &#8220;What your Friends can share about you&#8221; in your privacy settings (in my guide on SocialMediaSecurity.com this is what I recommend as well).</p>
<p>I will be updating my Facebook Privacy &amp; Security Guide over on <a href="http://socialmediasecurity.com">SocialMediaSecurity.com</a> to reflect all of these changes soon.  In the meantime, tell your friends on Facebook about these settings and check out a few other good articles on the recent changes.  Here are three articles I recommend reading: <a href="http://theharmonyguy.com/2010/04/21/pros-and-cons-of-todays-facebook-announcements/">Pros and Cons of Today’s Facebook Announcements</a> by theharmonyguy, <a href="http://www.eff.org/deeplinks/2010/04/how-opt-out-facebook-s-instant-personalization">How to Opt Out of Facebook’s Instant Personalization</a> (with a nice video walk-through) by the EFF and <a href="http://mashable.com/2010/04/21/open-graph-privacy/">Facebook Open Graph: What it Means for Privacy</a> by Mashable.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2010/04/privacy-of-open-graph-social-plugins-and-instant-personalization-on-facebook/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Notacon 7 &#8211; Things to Do and Talks to Attend</title>
		<link>http://www.spylogic.net/2010/04/notacon-7-things-to-do-and-talks-to-attend/</link>
		<comments>http://www.spylogic.net/2010/04/notacon-7-things-to-do-and-talks-to-attend/#comments</comments>
		<pubDate>Thu, 15 Apr 2010 19:23:25 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Cleveland]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[art]]></category>
		<category><![CDATA[notacon]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[speaking]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[zombies]]></category>

		<guid isPermaLink="false">http://www.spylogic.net/?p=435</guid>
		<description><![CDATA[The con that is Notacon is upon us. Notacon is one of the best con&#8217;s I have ever attended!  It&#8217;s a great mix of hacking, security, art, technology and everything in between.  It&#8217;s also small enough to network with others&#8230;oh, and its in Cleveland which means its affordable!  Things get started tonight with a free [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-436" title="NAClogo" src="http://www.spylogic.net/wp-content/uploads/2010/04/NAClogo.jpg" alt="" width="161" height="161" />The con that is Notacon is upon us. Notacon is one of the best con&#8217;s I have ever attended!  It&#8217;s a great mix of hacking, security, art, technology and everything in between.  It&#8217;s also small enough to network with others&#8230;oh, and its in Cleveland which means its affordable!  <strong>Things get started tonight with a free preview beginning at 7pm!</strong> Some of the speakers will be giving previews of their talks so go check it out if you can.</p>
<p>Just like previous years, there are some really cool events you need to attend including <a href="http://www.notacon.org/events.html#slide">Whose Slide is it Anyway</a>, the <a href="http://blog.notacon.org/?p=348">Friday night experience</a> and <a href="http://www.notacon.org/blockparty.html">Blockparty</a>!  This year the <a href="http://www.notacon.org/events.html#lockpick">lock picking village</a> is sponsored by <a href="http://groups.google.com/group/cleveland-locksport-announcements?pli=1">Cleveland Locksport</a> and be sure to check out Deviant Ollam&#8217;s new challenge the <a href="http://www.notacon.org/events.html#defiantbox">Defiant Box</a>. <a href="http://securityjustice.com">Security Justice</a> will also have a live show at 11pm Friday night in the Notacon Radio room. As for talks, this years lineup looks great!  Here are my picks of talks to attend this year:</p>
<p><strong>Friday</strong><br />
Mick Douglas (from PaulDotCom Security Weekly) &#8211; <a href="http://www.notacon.org/speakers.html#MickDouglas">U R Doin it Wrong Info Disclosure over P2P Networks</a><br />
Tiffany Rad &#8211; <a href="http://www.notacon.org/speakers.html#Rad">Hacking Your Car: Reverse Engineering Protocols, Legalities and the Right to Repair Act</a><br />
Brad Smith &#8211; <a href="http://www.notacon.org/speakers.html#BradSmith">Stealing from God!</a><br />
Emily Schooley &#8211; <a href="http://www.notacon.org/speakers.html#Schooley">Independent Filmmaking &#8211; Bringing Your Ideas from Paper to the Screen, and Everything in Between</a><br />
Nicolle &#8220;rogueclown&#8221; Neulist &#8211; <a href="http://www.notacon.org/speakers.html#rogueclown">Hey, Don&#8217;t Call That Guy A Noob: Toward a More Welcoming Hacker Community </a><br />
int eighty &#8211; <a href="http://www.notacon.org/speakers.html#inteighty">Malicious PDF Analysis</a><br />
catfood &#8211; <a href="http://www.notacon.org/speakers.html#catfood">Why Your Software Project Sucks (and how to make it not suck)</a><br />
Dead Addict &#8211; <a href="http://www.notacon.org/speakers.html#DeadAddict">Hidden Trust relationships, an exploration<br />
</a>Jeff &#8220;ghostnomad&#8221; Kirsch &#8211; <a href="http://www.notacon.org/speakers.html#Kirsch">The Haiku of Security: Complexity through Simplicity</a><br />
David Kennedy (rel1k) &#8211; <a href="http://www.notacon.org/speakers.html#DavidKennedy">The Social-Engineering Toolkit (SET) &#8211; Putting cool back into SE</a></p>
<p><strong>Saturday</strong><br />
Adrian Crenshaw (IronGeek) &#8211; <a href="http://www.notacon.org/speakers.html#AdrianCrenshaw">Anti-forensics</a><br />
James Arlen, Chris Clymer, Mick Douglas, and Brandon Knight &#8211; <a href="http://www.notacon.org/speakers.html#SocialEngineering">Social Engineering Security Into Your Business</a><br />
James Arlen, Leigh Honeywell, Tiffany Rad and Jillian Loslo &#8211; <a href="http://www.notacon.org/speakers.html#FuturePanel">Hacking The Future: Weaponizing the Next Generation</a><br />
Melissa Barron &#8211; <a href="http://www.notacon.org/speakers.html#MelissaBarron">Hacking 73H 0r3g0n 7r41L for the Apple ][</a><br />
Tom Eston, Chris Clymer, Matthew Neely, The Confused Greenies &#8211; <a href="http://www.notacon.org/speakers.html#ZombieApocalypse">Surviving the Zombie Apocalypse</a> (<a href="http://www.youtube.com/watch?v=Rt_EkpFwQFQ">did you see our preview?</a>)<br />
James Arlen &#8211; <a href="http://www.notacon.org/speakers.html#JamesArlen">SCADA and ICS for Security Experts: How to avoid cyberdouchery</a><br />
Eleanor Saitta &#8211; <a href="http://www.notacon.org/speakers.html#Saitta2">Designing the Future of Sex</a></p>
<p>Also on Saturday night don&#8217;t miss <a href="http://dualcoremusic.com/nerdcore/">Dual Core</a> at 8pm!  I&#8217;ll be around at the con hanging out so if you see me stop and say Hi.  See you there!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2010/04/notacon-7-things-to-do-and-talks-to-attend/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Social Zombies II Slides, Video and Demos from Shmoocon</title>
		<link>http://www.spylogic.net/2010/02/social-zombies-ii-slides-video-and-demos-from-shmoocon/</link>
		<comments>http://www.spylogic.net/2010/02/social-zombies-ii-slides-video-and-demos-from-shmoocon/#comments</comments>
		<pubDate>Fri, 26 Feb 2010 06:35:15 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[linkedin]]></category>
		<category><![CDATA[shmoocon]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[zombies]]></category>

		<guid isPermaLink="false">http://www.spylogic.net/?p=422</guid>
		<description><![CDATA[Some of you have asked for the slides and video from the talk I did at Shmoocon with Kevin Johnson and Robin Wood titled &#8220;Social Zombies II: Your Friends Need More Brains&#8221;.  I had posted these on the Twitter but I wanted to get these links up in one static location, the blog! You can [...]]]></description>
			<content:encoded><![CDATA[<p>Some of you have asked for the slides and video from the talk I did at Shmoocon with Kevin Johnson and Robin Wood titled &#8220;Social Zombies II: Your Friends Need More Brains&#8221;.  I had posted these on the Twitter but I wanted to get these links up in one static location, the blog!</p>
<p>You can view the slides on my <a href="http://www.slideshare.net/agent0x0/social-zombies-ii-your-friends-need-more-brains-3107346">SlideShare </a>page and the video is available on <a href="http://www.vimeo.com/9412753">Vimeo</a>.  In addition, Robin and I showed two demos during the talk.  First was my <a href="http://www.youtube.com/watch?v=chvwtGPkAIQ">Facebook Application Autopwn with BeEF Demo</a> and Robin&#8217;s new <a href="http://www.vimeo.com/9295657">KreiosC2 demo using LinkedIn with Windows support</a>.  Who knows, there might be more social zombies in the future! <img src='http://www.spylogic.net/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2010/02/social-zombies-ii-slides-video-and-demos-from-shmoocon/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Facebook SPAM on BlackBerry Devices</title>
		<link>http://www.spylogic.net/2010/02/facebook-spam-on-blackberry-devices/</link>
		<comments>http://www.spylogic.net/2010/02/facebook-spam-on-blackberry-devices/#comments</comments>
		<pubDate>Mon, 15 Feb 2010 20:37:39 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[blackberry]]></category>
		<category><![CDATA[bugs]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[socialnetworking]]></category>
		<category><![CDATA[socnetsec]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.spylogic.net/?p=413</guid>
		<description><![CDATA[I always thought the Facebook Application for BlackBerry was a buggy, slow piece of junk.  Now I have noticed that this application is being abused by spammers to propagate Viagra and Percocet SPAM.  The screen shot to the right is an actual Facebook notification I received on my BlackBerry. There seems to be an interesting [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.spylogic.net/wp-content/uploads/2010/02/Facebook_AppSpam.jpg"><img class="alignright size-medium wp-image-414" title="Facebook_AppSpam" src="http://www.spylogic.net/wp-content/uploads/2010/02/Facebook_AppSpam-300x225.jpg" alt="" width="250" height="187" /></a>I always thought the <a href="http://na.blackberry.com/eng/devices/features/social/facebook.jsp?">Facebook Application for BlackBerry</a> was a buggy, slow piece of junk.  Now I have noticed that this application is being abused by spammers to propagate Viagra and Percocet SPAM.  The screen shot to the right is an actual Facebook notification I received on my BlackBerry.</p>
<p>There seems to be an interesting bug in the Facebook Application for BlackBerry in which a spammer can spoof the &#8220;facebookmail.com&#8221; domain to have SPAM messages show up in your notifications list within the BlackBerry Facebook application.  This only works if you have the Facebook for BlackBerry Application installed AND you have an email account configured on your BlackBerry (yes, this includes a corporate email account as well).  The email account you have configured on your BlackBerry is where you actually receive the SPAM message, not through Facebook.</p>
<p>The Facebook Application for BlackBerry appears to notify on any new email in one of your BlackBerry mailbox&#8217;s with &#8220;*.facebookmail.com&#8221; in the sender or return-path field.  This is a win for the spammer because now you think Facebook is spamming you and with the addition of an email, you&#8217;re more tempted to click on the link.  The Facebook Application for BlackBerry is <a href="http://www.spylogic.net/2009/05/potential-dangers-of-blackberry-syncing-applications/">no stranger to controversy</a> and this particular bug <a href="http://www.pocketberry.com/2010/02/02/facebook-app-for-blackberry-gets-spam/">has been noticed recently</a> by others as well.  It also appears that this bug only affects the BlackBerry Facebook application.  When testing the iPhone app I couldn&#8217;t replicate the issue.</p>
<p>To test this bug I used <a href="http://www.exim.org/">EXIM4</a> in Ubuntu as a mail relay with mailtools to send the email.  This allowed me to send a spoofed email as &#8220;agent0x0@facebookmail.com&#8221; to one of the email accounts I have configured on my BlackBerry.  Here are screen shots of the spoofed email in my inbox and what it looks like in the Facebook Application for BlackBerry:</p>
<p><a href="http://www.spylogic.net/wp-content/uploads/2010/02/Facebook_AppSpam_Email.jpeg"><img class="alignnone size-medium wp-image-415" title="Facebook_AppSpam_Email" src="http://www.spylogic.net/wp-content/uploads/2010/02/Facebook_AppSpam_Email-300x172.jpg" alt="" width="300" height="172" /></a></p>
<p><a href="http://www.spylogic.net/wp-content/uploads/2010/02/Facebook_AppSpam2.jpg"><img class="alignnone size-medium wp-image-416" title="Facebook_AppSpam2" src="http://www.spylogic.net/wp-content/uploads/2010/02/Facebook_AppSpam2-300x224.jpg" alt="" width="300" height="224" /></a></p>
<p>My opinion is that a mobile Facebook application should never be polling your personal email for these messages&#8230;but then again this could be a &#8220;feature&#8221; of this nicely designed application, right? <img src='http://www.spylogic.net/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />   Special thanks to <a href="http://twitter.com/secureideas">Kevin Johnson</a> for helping with some of the research/testing.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2010/02/facebook-spam-on-blackberry-devices/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Beware of Evil Facebook Groups</title>
		<link>http://www.spylogic.net/2010/01/beware-of-evil-facebook-groups/</link>
		<comments>http://www.spylogic.net/2010/01/beware-of-evil-facebook-groups/#comments</comments>
		<pubDate>Wed, 06 Jan 2010 06:12:40 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[fail]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[socialmedia]]></category>
		<category><![CDATA[socialnetworking]]></category>
		<category><![CDATA[socnetsec]]></category>

		<guid isPermaLink="false">http://www.spylogic.net/?p=393</guid>
		<description><![CDATA[Some of my Facebook friends are probably wondering why I would fall into the trap of the magical &#8220;dislike button&#8221; hype that seems to be sweeping across Facebook right now.  In a little social experiment and hopefully an awareness exercise for some of my non-security friends I created a Facebook group based off of similar [...]]]></description>
			<content:encoded><![CDATA[<p>Some of my Facebook friends are probably wondering why I would fall into the trap of the magical &#8220;dislike button&#8221; hype that seems to be sweeping across Facebook right now.  In a little social experiment and hopefully an awareness exercise for some of my non-security friends I created a Facebook group based off of similar ones I have seen called <a onclick="ft(&quot;4:10:263:1209954437:::0:lf::236264339243&quot;);" href="http://www.facebook.com/group.php?gid=412502945533&amp;ref=nf">The REAL Dislike Button™ is Finally Here! Add it Now!</a>.  The group is harmless even if it looks like there is scary JavaScript code in the instructions to &#8220;turn your friends blue&#8221;.  If you click on the link it takes you to one of my favorite YouTube video&#8217;s.  <img src='http://www.spylogic.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>The point is that these fake groups are targeting Facebook users thinking that Facebook has these new &#8220;features&#8221; like a dislike button and even ones like &#8220;see who viewed your profile&#8221;.  Folks, these techniques and/or modifications to Facebook don&#8217;t exist.  Sorry.  Just in the last week I have seen more and more of my Facebook friends sharing links to these groups.  Almost all of the groups I have looked at that were being shared lead to very bad places which I will demonstrate below.</p>
<p><strong>Example #1 &#8211; The Typical &#8220;Get the DISLIKE BUTTON&#8221; Scam</strong><br />
In this example we have one of *many* groups that promise you the uber magic secret &#8220;dislike&#8221; button if you just join the group, invite your friends to do the same and follow some strange link off to Neverland.  This group has 1,162,238 members.  I wish I was making that number up.</p>
<p><a href="http://www.spylogic.net/wp-content/uploads/2010/01/dislike_button1.jpg"><img class="alignnone size-medium wp-image-400" title="dislike_button" src="http://www.spylogic.net/wp-content/uploads/2010/01/dislike_button1-300x206.jpg" alt="" width="300" height="206" /></a></p>
<p>The first thing you will notice is that there is a link to a Facebook profile they want you to friend.  That profile was deleted (your first clue).  Next, they want you to check out a link in Step 5.  That link sends you here:</p>
<p><a href="http://www.spylogic.net/wp-content/uploads/2010/01/link_from_dislike_group.jpg"><img class="alignnone size-medium wp-image-395" title="link_from_dislike_group" src="http://www.spylogic.net/wp-content/uploads/2010/01/link_from_dislike_group-300x205.jpg" alt="" width="300" height="205" /></a></p>
<p>Which will eventually install some nasty adware/spyware on your Windows machine called <a href="http://www.bitdefender.com/VIRUS-1000252-en--Adware.Mywebsearch.DV.html">Adware.Mywebsearch.DV</a>.  It&#8217;s not easy to get rid of.</p>
<p>In a similar group like the one above with a mere 697,375 members the last link takes you to this:</p>
<p><a href="http://www.spylogic.net/wp-content/uploads/2010/01/dislike2_linkfromgroup.jpg"><img class="alignnone size-medium wp-image-396" title="dislike2_linkfromgroup" src="http://www.spylogic.net/wp-content/uploads/2010/01/dislike2_linkfromgroup-300x206.jpg" alt="" width="300" height="206" /></a></p>
<p>If you go through with entering in your cell phone number and getting the confirmation code per the instructions you have just signed up for a monthly charge to your cell phone account to the tune of $9.99 per month.  The monthly charge details is in the very tiny text you can hardly read.  Nice.  But wait, if you were smart enough to try and close the quiz window, you get this pop-up:</p>
<p><a href="http://www.spylogic.net/wp-content/uploads/2010/01/dummy.jpg"><img class="alignnone size-medium wp-image-397" title="dummy" src="http://www.spylogic.net/wp-content/uploads/2010/01/dummy-300x118.jpg" alt="" width="300" height="118" /></a></p>
<p>Really?  Hopefully you don&#8217;t fall for that one even though it shows your real city.</p>
<p><strong>Example #2 &#8211; The Typical &#8220;See everyone who viewed your profile&#8221; Scam</strong></p>
<p>This is one of my favorites as this is another impossible feat of Facebook technology.  Here is what the screen shot look like:</p>
<p><a href="http://www.spylogic.net/wp-content/uploads/2010/01/See_Everyone2_ScreenShot.jpg"><img class="alignnone size-medium wp-image-398" title="See_Everyone2_ScreenShot" src="http://www.spylogic.net/wp-content/uploads/2010/01/See_Everyone2_ScreenShot-300x154.jpg" alt="" width="300" height="154" /></a></p>
<p>Note the PhotoShop job on the notification window showing who has &#8220;viewed&#8221; your profile.  Clicking on the bit.ly link leads you to another quiz application or adware/spyware or other forms of dangerous malware.  Don&#8217;t worry, there are *lots* of these groups out there. Good times.</p>
<p>So the lesson here is&#8230;don&#8217;t click on anything in these groups that tempt you with magical Facebook powers!  If it seems too good to be true, it probably is!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2010/01/beware-of-evil-facebook-groups/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Twitter: You’re Doing It Wrong!</title>
		<link>http://www.spylogic.net/2009/12/twitter-youre-doing-it-wrong/</link>
		<comments>http://www.spylogic.net/2009/12/twitter-youre-doing-it-wrong/#comments</comments>
		<pubDate>Sat, 12 Dec 2009 16:20:21 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[fail]]></category>
		<category><![CDATA[socialmedia]]></category>
		<category><![CDATA[socialnetworking]]></category>
		<category><![CDATA[socnetsec]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.spylogic.net/?p=366</guid>
		<description><![CDATA[I see some crazy, mind blowing things posted by people on social networks but this recent tweet I saw might take the cake.  It&#8217;s one thing to post something on Facebook where you have the ability to lock down who might see your status updates but Twitter has very little control over this.  In fact, [...]]]></description>
			<content:encoded><![CDATA[<p>I see some crazy, mind blowing things posted by people on social networks but this recent tweet I saw might take the cake.  It&#8217;s one thing to post something on Facebook where you have the ability to lock down who might see your status updates but Twitter has very little control over this.  In fact, if you post something to Twitter (even with a private profile) it can be re-tweeted and/or copied by your friends.</p>
<p>Regardless of settings I think that there are just *stupid* people using social networks.  In fact, I think that even if social networks didn&#8217;t exist these people would still be classified as ones with &#8220;no brain cells&#8221; (no pun intended with this example).  For example, here is tweet from a girl talking about a job interview she has scheduled with some company:</p>
<p><img class="alignnone size-full wp-image-367" title="fail_twitter1" src="http://www.spylogic.net/wp-content/uploads/2009/12/dumbgirl_twitter1.jpg" alt="fail_twitter1" width="623" height="430" /></p>
<p>Now if that wasn&#8217;t bad enough&#8230;check out her profile picture:</p>
<p><img class="alignnone size-full wp-image-368" title="fail_twitter2" src="http://www.spylogic.net/wp-content/uploads/2009/12/dumbgirl_twitter2.jpg" alt="fail_twitter2" width="625" height="466" /></p>
<p>I have nothing else to say but&#8230;<strong>FAIL</strong>.  Perhaps this is the start of a new series of blog posts.  <img src='http://www.spylogic.net/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2009/12/twitter-youre-doing-it-wrong/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Facebook Privacy Settings: For Better or For Worse?</title>
		<link>http://www.spylogic.net/2009/12/new-facebook-privacy-settings-for-better-or-for-worse/</link>
		<comments>http://www.spylogic.net/2009/12/new-facebook-privacy-settings-for-better-or-for-worse/#comments</comments>
		<pubDate>Thu, 10 Dec 2009 05:59:26 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Privacy on the Internetz]]></category>
		<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[bots]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[informationgathering]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[socialmedia]]></category>
		<category><![CDATA[socialnetworking]]></category>
		<category><![CDATA[socnetsec]]></category>
		<category><![CDATA[zombies]]></category>

		<guid isPermaLink="false">http://www.spylogic.net/?p=371</guid>
		<description><![CDATA[Everyone has probably already heard that Facebook rolled out new privacy settings today.  If you haven&#8217;t seen them or gotten the following pop-up box on login&#8230;you will soon: There are a great deal of articles already out about how this is such a great improvement and how these new settings give you more control over [...]]]></description>
			<content:encoded><![CDATA[<p>Everyone has probably already heard that Facebook rolled out new privacy settings today.  If you haven&#8217;t seen them or gotten the following pop-up box on login&#8230;you will soon:</p>
<p><a href="http://www.spylogic.net/wp-content/uploads/2009/12/message1.jpg"><img class="size-medium wp-image-375  alignleft" title="message1" src="http://www.spylogic.net/wp-content/uploads/2009/12/message1-300x134.jpg" alt="message1" width="300" height="134" /></a></p>
<p>There are a great deal of articles already out about how this is such a great improvement and how these new settings give you more control over your privacy.  However, I would argue that these settings may possibly open up more issues then they are trying to prevent.  The best article on the new settings and the privacy implications is the one that the <a href="http://www.eff.org/">Electronic Frontier Foundation</a> (EFF) released today titled: <a href="http://www.eff.org/deeplinks/2009/12/facebooks-new-privacy-changes-good-bad-and-ugly">Facebook&#8217;s New Privacy Changes: The Good, The Bad, and The Ugly</a>.  I recommend everyone (no pun intended) read this article as it provides much more detail then I will provide in this post.</p>
<p>What I want to do is provide you with a summary of the good and the bad of the new privacy settings.  I also want to give a security professional&#8217;s point of view on these settings.  As a penetration tester I can tell you that my job just got way easier!  You may have read my series on <a href="http://www.spylogic.net/2009/10/enterprise-open-source-intelligence-gathering-part-1-social-networks/">Enterprise Open Source Intelligence Gathering</a> in which I tell you how you can find information on social networks about your company and employees.  Well, searching for information on Facebook just got easier thanks to status updates being available using new technology like <a href="http://googleblog.blogspot.com/2009/12/relevance-meets-real-time-web.html">Google Real-time Search</a>!  Ok, on to the better and the worse!</p>
<p><strong>The Better?</strong></p>
<ul>
<li>The new way privacy settings are &#8220;managed&#8221; is a good thing.  It&#8217;s easier to find and navigate through the settings.</li>
<li>I like that they ask you for your password to change privacy settings.  It&#8217;s just another layer.  Now, this doesn&#8217;t help much if you have a keylogger installed but it seems they put this in to prevent bots that may have taken over your account access to your settings.  Again, not fool proof but another layer.</li>
<li>The ability to fully customize privacy settings on all the content you post.  So for example, you can specify if you want everyone on the Internet to view your status updates (more on that in a minute) or Friends, Friends of Friends and Custom.</li>
<li>Users are now somewhat &#8220;forced&#8221; to check out their privacy settings.  It&#8217;s more accessible that&#8217;s for sure.</li>
</ul>
<p><strong>The Worse?</strong></p>
<ul>
<li><strong>Your Name, Profile Picture, Gender, Current City, Networks, Friend List, and Pages are all available to be viewed by EVERYONE on Facebook!</strong> You cannot change these settings at all.  Note, there is a way to remove your entire <strong>Friends List</strong> from your profile but it&#8217;s all or nothing!  <a href="http://www.spylogic.net/wp-content/uploads/2009/12/hide_friends.jpg">Here is a screen shot of this</a>. You have to set it in your profile page using the &#8220;edit&#8221; button and check the box.These changes are quite disturbing considering that you used to be able to restrict this type of information.  I really believe that Facebook has done this on purpose so *more* information is being shared about you while stating &#8220;enhanced&#8221; more granular privacy settings.  If you have been to one of my talks in the past I always mention that social networks need to find ways to make money.  The way they make money is off of the information you share!  If you don&#8217;t get a choice about the basic information anymore&#8230;that&#8217;s more money in their pocket at the expense of your privacy.<strong><br />
</strong></li>
<li><strong>What about the security ramifications of this?</strong> It opens up a whole new world for cyberstalking, predators and other attackers.  If you were someone that didn&#8217;t feel comfortable sharing this information in the first place, your choice is gone.  Sure, you can lock down your profile so no one can search for you but if you do that&#8230;why are you on Facebook to begin with?  You *have* to let your real friends search for you at some point!</li>
<li>By default Facebook &#8220;suggests&#8221; that you set your status updates to &#8220;Everyone&#8221;.  Here is the thing with status updates&#8230;.<strong>Everyone</strong> means everyone on the Internet!  This is where new technology like <a href="http://googleblog.blogspot.com/2009/12/relevance-meets-real-time-web.html">Google RTS</a> comes into play.  Imagine how easy it will be to find the latest information on &#8220;Tiger Woods&#8221; or now everything YOU are saying on Facebook, Twitter and other social networks.  Enter in some social engineering and things just got easier for attackers looking to use you or your information (which is easy to figure out now that I can see your friends, and things that interest you via the pages your a fan of).</li>
<li>Lastly, Facebook removed the ability to prevent Facebook applications your friends installed from pulling your &#8220;public&#8221; information.  That option is now gone and applications that your friends install can now view your &#8220;public&#8221; info.  Remember kids, &#8220;public&#8221; info is now: <strong>Your Name, Profile Picture, Gender, Current City, Networks, Friend List, and Pages.</strong></li>
</ul>
<p>One final note&#8230;be sure to double check all your privacy settings after you run the wizard.  I found a few settings that reverted back to settings I never had.  So what are your thoughts?  Will this make you lock your profile down more?  Do you care?  Is privacy dead anyway? Will Zombies destroy us all? <img src='http://www.spylogic.net/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2009/12/new-facebook-privacy-settings-for-better-or-for-worse/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Social Zombies at OWASP AppSec DC this Week</title>
		<link>http://www.spylogic.net/2009/11/social-zombies-at-owasp-appsec-dc-this-week/</link>
		<comments>http://www.spylogic.net/2009/11/social-zombies-at-owasp-appsec-dc-this-week/#comments</comments>
		<pubDate>Mon, 09 Nov 2009 19:42:15 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[bots]]></category>
		<category><![CDATA[defcon]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[kreiosc2]]></category>
		<category><![CDATA[myspace]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[socialnetworking]]></category>
		<category><![CDATA[socnetsec]]></category>
		<category><![CDATA[speaking]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[vegas]]></category>
		<category><![CDATA[zombies]]></category>

		<guid isPermaLink="false">http://www.spylogic.net/?p=361</guid>
		<description><![CDATA[Continuing the zombie apocalypse from Defcon&#8230;Kevin Johnson and I will again be presenting &#8220;Social Zombies: Your Friends Want to Eat Your Brains&#8221; at this week&#8217;s OWASP AppSec DC conference.  We will be speaking Thursday, November 12th at 2:10 in room 146c.  We will have some new material and updates from the presentation we gave at [...]]]></description>
			<content:encoded><![CDATA[<p>Continuing the zombie apocalypse from Defcon&#8230;Kevin Johnson and I will again be presenting <a href="http://www.owasp.org/index.php/Social_Zombies:_Your_Friends_Want_to_Eat_Your_Brains">&#8220;Social Zombies: Your Friends Want to Eat Your Brains&#8221;</a> at this week&#8217;s <a href="http://appsecdc.org/">OWASP AppSec DC </a>conference.  We will be speaking <strong>Thursday, November 12th at 2:10 in room 146c</strong>.  We will have some new material and updates from the presentation we gave at Defcon 17 this year including the release of a new version of Robin Wood&#8217;s <a href="http://www.digininja.org/projects/kreiosc2.php">KreiosC2</a> (beyond Twitter for C&amp;C).  If your going to the conference we hope to see you there!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2009/11/social-zombies-at-owasp-appsec-dc-this-week/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Enterprise Open Source Intelligence Gathering – Part 3 Monitoring and Social Media Policies</title>
		<link>http://www.spylogic.net/2009/10/enterprise-open-source-intelligence-gathering-part-3-monitoring/</link>
		<comments>http://www.spylogic.net/2009/10/enterprise-open-source-intelligence-gathering-part-3-monitoring/#comments</comments>
		<pubDate>Fri, 30 Oct 2009 03:36:48 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[googledorks]]></category>
		<category><![CDATA[informationgathering]]></category>
		<category><![CDATA[linkedin]]></category>
		<category><![CDATA[maltego]]></category>
		<category><![CDATA[myspace]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[rss]]></category>
		<category><![CDATA[socialmedia]]></category>
		<category><![CDATA[socialnetworking]]></category>
		<category><![CDATA[socnetsec]]></category>
		<category><![CDATA[speaking]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[yahoopipes]]></category>

		<guid isPermaLink="false">http://www.spylogic.net/?p=345</guid>
		<description><![CDATA[This is the final article in my series on Enterprise Open Source Intelligence Gathering.  This information relates to the main topics from my presentation that I am giving this week at the 7th Annual Ohio Information Security Summit.  For more background information, see part one.  If you missed part two (blogs, message boards and metadata) [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-346" title="monitoring" src="http://www.spylogic.net/wp-content/uploads/2009/10/monitoring.jpg" alt="monitoring" width="300" height="225" />This is the final article in my series on Enterprise Open Source Intelligence Gathering.  This information relates to the main topics from my presentation that I am giving this week at the <a href="http://informationsecuritysummit.org/"> 7th Annual Ohio Information Security Summit</a>.  For more background information, see <a href="../2009/10/enterprise-open-source-intelligence-gathering-part-1-social-networks/">part one</a>.  If you missed part two (blogs, message boards and metadata) you can check that out <a href="http://www.spylogic.net/2009/10/enterprise-open-source-intelligence-gathering-%E2%80%93-part-2-blogs-message-boards-and-metadata/">here</a>.  This last article will be about putting together a simple monitoring program/toolkit and creating a social media policy for your company.</p>
<p><strong>OSINT and Monitoring</strong><br />
After reading this series you are probably asking yourself&#8230;what do I do will all of these feeds and information that I have gathered?  Much of the information you have found about your company may be pretty overwhelming and you might find there is a ton of noise to filter through to get to the &#8220;good stuff&#8221;.  The next sections of this article will hopefully help you organize these feeds so you can begin a basic monitoring program.</p>
<p><strong>What do you want to monitor?</strong><br />
This first thing you want to ask yourself&#8230;what do you want to monitor and what is most important?  You probably have noticed that it would be difficult to monitor the entire Internet so focus on what is relevant to your company or business.  Also, you want to pay particular attention to the areas of social media that your business has a presence on.  For example, if your business has a Facebook page, LinkedIn group and Twitter account you should be paying special attention to these first.  Why?  These are the sites that you have most likely allowed certain employees to use this form of media for business purposes.  Lastly, keep in mind that choosing what to monitor should be a group collaborative effort.  Get your marketing and public relations people involved in the decision making process.  As a bonus, it helps with making security everyone&#8217;s business.</p>
<p><strong>Free tools to aggregate this information</strong><br />
Lets discuss briefly some tools to aggregate and monitor all the information sources you have decided as important.  There are two tools that I will talk about.  Yahoo! Pipes and RSS readers (specifically Google Reader).</p>
<p><strong>1. Yahoo! Pipes</strong><br />
First, what is <a href="http://pipes.yahoo.com/pipes/">Yahoo! Pipes</a>?  The best description is probably found on the Yahoo! Pipes main page:</p>
<blockquote><p>&#8220;Pipes is a powerful composition tool to aggregate, manipulate, and mashup content from around the web.  Like Unix pipes, simple commands can be combined together to create output that meets your needs:</p>
<p>- combine many feeds into one, then sort, filter and translate it.<br />
- geocode your favorite feeds and browse the items on an interactive map.<br />
- grab the output of any Pipes as RSS, JSON, KML, and other formats.</p></blockquote>
<p>The great thing about pipes is that there are already many different mashups that have already been created!  If you find one that doesn&#8217;t do what you like it to&#8230;you can simply copy a pipe, modify it and use it as your own.  Creating a pipe is really easy as well.  Yahoo! provides good documentation on their site even with video tutorials if you are lost.  Everything is done in a neat visual &#8220;drop-n-drag&#8221; GUI environment.  For example, you could take some of the sites that you find a bit more difficult to monitor, configure them in a pipe and send the output to RSS.  Once you have an RSS feed you can plug this into a RSS reader (like Google Reader) for monitoring.  Here are a few of my favorite pipes (pre-built) that can be used for monitoring:</p>
<p><a href="http://pipes.yahoo.com/update_maker/social_media_fire_hose">Social Media Firehose</a><br />
<a href="http://pipes.yahoo.com/socialmedia/monitoring">Social Media Monitoring Tool</a><br />
<a href="http://pipes.yahoo.com/jstein/ttix2009">Aggregate Social Media Feeds by User &amp; Tag</a><br />
<a href="http://pipes.yahoo.com/geekygirldawn/a172f4c77b9a1de17e626f5928d60185">Twitter Sniffer for Brands</a><br />
<a href="http://pipes.yahoo.com/jasonsilver/facebookgroup">Facebook Group RSS Feed</a>, improved version <a href="http://pipes.yahoo.com/andrelevy/facebook">here</a></p>
<p><strong>2. Google Reader or your favorite RSS reader</strong><br />
The second part of your monitoring toolkit is to put your Yahoo! Pipe RSS feeds and the other feeds you determined as important and put them into the RSS reader of your choice.  I personally like Google Reader because it&#8217;s easy to use and manage.  However, you may prefer a desktop client or some other type of reader&#8230;all up to you.</p>
<p><strong>What&#8217;s easy and works best?</strong><br />
First, assign someone to look at the information you are monitoring.  This should be someone in your information security department and someone with social media skill sets.  Next, create RSS Feeds from identified sites and utilize Yahoo! Pipes to customize and filter out content if you need to.  Finally, plug these feeds into your RSS reader and set up procedures for monitoring.  When will you check these feeds? What happens if the monitoring person is out?  Is there a backup for this person?  These are just a few of the things you need to think about when putting together these procedures.  There may be many more (or less) depending on your business.  Lastly, for sites you can’t monitor automatically determine manual methods and be sure to build procedures around them.</p>
<p><strong>What is the company social media strategy? Do you even have one?</strong><br />
The first thing you need to do before you create policies or standards around what employees can or can&#8217;t do on social media/networking sites (related to your business), is to define a social media strategy.  Without a strategy defined it would be nearly impossible to determine a monitoring program without knowing what areas of social media your business is going to participate in.  This is a very important step and is something that your marketing/public relations/HR departments need to determine before security gets involved.</p>
<p><strong>Internet postings or the &#8220;social media&#8221; policy</strong><br />
What if you have policies for Internet usage already in your company?  If you do, have you checked to see if they include specific things like social networks?  How about commenting on company news or issues on public social networks?  This is an area where many of the &#8220;standard&#8221; Infosec or HR policies don&#8217;t cover or don&#8217;t mention procedures about how employees use this new world of social media.  The other important part is that you need to partner with marketing/public relations/HR to collaborate on this policy.  The design and creation needs to have input from all of these areas of the business, especially these groups because they are going to be the main drivers for the use of social media.  Lastly, what is acceptable for employees to post?  Keep in mind that employees have Internet access *everywhere* nowadays.  iPhones, smartphones, Google phones&#8230;employees have these and guess what?  They are most likely using them at work.  How do you know that they are not commenting about company confidential business?  With this new generation of devices&#8230;the line between personal and company business will continue to blur. Oh, and this is just one simple example!</p>
<p><strong>Examples of good policies to reference</strong><br />
So where do you go from here?  Create the policy!  The last part of this article has examples of good policies that you can reference when creating your own policies.  There is lots of good information in the following links and you can customize these for your own environment and business situation:</p>
<p><a href="http://blogs.cisco.com/news/comments/ciscos_internet_postings_policy/">Cisco Internet Postings Policy</a><br />
<a href="http://www.intel.com/sites/sitewide/en_US/social-media.htm">Intel Social Media Policy</a><br />
<a href="http://http://www.cio.com/article/505644/4_Tips_for_Writing_a_Great_Social_Media_Security_Policy?source=rss_security">4 Tips for Writing a Good Social Media Policy</a><br />
<a href="http://clicktoclient.com/10-steps-to-creating-a-social-media-policy-for-your-company/">10 Steps to Creating a Social Media Policy for your Company</a></p>
<p>Remember, monitoring the use of social media and creating policies around them is new and potentially uncharted territory for many organizations.  Hopefully with this series (and the related presentation) will help guide you and your organization to make the right decisions on finding information about your company, creating a monitoring program and working with your business partners to create the right policies for your business.</p>
<p><strong>UPDATE:</strong> You can <a href="http://www.slideshare.net/agent0x0/enterprise-open-source-intelligence-gathering">download my slide deck now on SlideShare</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2009/10/enterprise-open-source-intelligence-gathering-part-3-monitoring/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Enterprise Open Source Intelligence Gathering – Part 2 Blogs, Message Boards and Metadata</title>
		<link>http://www.spylogic.net/2009/10/enterprise-open-source-intelligence-gathering-%e2%80%93-part-2-blogs-message-boards-and-metadata/</link>
		<comments>http://www.spylogic.net/2009/10/enterprise-open-source-intelligence-gathering-%e2%80%93-part-2-blogs-message-boards-and-metadata/#comments</comments>
		<pubDate>Wed, 28 Oct 2009 21:00:36 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[googledorks]]></category>
		<category><![CDATA[informationgathering]]></category>
		<category><![CDATA[linkedin]]></category>
		<category><![CDATA[maltego]]></category>
		<category><![CDATA[myspace]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[socialmedia]]></category>
		<category><![CDATA[socialnetworking]]></category>
		<category><![CDATA[socnetsec]]></category>
		<category><![CDATA[speaking]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.spylogic.net/?p=339</guid>
		<description><![CDATA[This post is part two of my three part series on Enterprise Open Source Intelligence Gathering.  This information relates to the presentation that I am giving this week at the 7th Annual Ohio Information Security Summit.  For more background information, see part 1.  Part three will be about putting together a simple monitoring program/toolkit and [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-340" title="message_board" src="http://www.spylogic.net/wp-content/uploads/2009/10/message_board.jpg" alt="message_board" width="300" height="225" />This post is part two of my three part series on Enterprise Open Source Intelligence Gathering.  This information relates to the presentation that I am giving this week at the <a href="http://informationsecuritysummit.org/"> 7th Annual Ohio Information Security Summit</a>.  For more background information, see <a href="http://www.spylogic.net/2009/10/enterprise-open-source-intelligence-gathering-part-1-social-networks/">part 1</a>.  Part three will be about putting together a simple monitoring program/toolkit and creating a Internet postings (social media) policy for your company.</p>
<p><a href="http://www.spylogic.net/2009/10/enterprise-open-source-intelligence-gathering-part-1-social-networks/">Part one of the series</a> discussed ways to gather OSINT on social networks and some of the challenges this creates.  Besides gathering OSINT on social networks there are many more sources of information that company information may be posted on.  These include blogs, message boards and document repositories.  One of the byproducts of finding documents is metadata, which I will explain in more detail below.</p>
<p><strong>OSINT and Blogs</strong><br />
Blogs can be searched via any traditional search engine, however, the challenge with blogs are not necessarily the posts themselves but the comments.  When it comes to blog posts the comments are usually where the action is, especially when it comes to your current and former employees (even customers) commenting on highly sensitive pubic relations issues that a company might be conducting damage control over.  The other point to make about commenting is that employees might be posting things that be violating one of your policies and cause brand reputation problems.  Examples of this are all the countless leaks of profits, downsizing, confidential information and more that the news media reports on.  Wouldn&#8217;t be great to be monitoring blogs and their comments to find these things out before they go viral?</p>
<p>Listed below are some of the blog and comment search sites that I recommend you add to your monitoring arsenal which I will talk about creating in part three:</p>
<p>Social Mention http://socialmention.com (has *great* comment search and RSS for monitoring)<br />
Google Blog Search http://blogsearch.google.com (great for creating RSS feeds and very customizable)<br />
Blogpulse http://www.blogpulse.com/ (has comment search)<br />
Technorati http://technorati.com/<br />
IceRocket http://www.icerocket.com/<br />
BackType http://www.backtype.com/ (has comment search)<br />
coComment http://www.cocomment.com/ (has comment search)</p>
<p><strong>OSINT and Message Boards</strong><br />
Message boards have always been a great source of OSINT.  Message boards date back before blogs were popular and are still widely used today.  Because there are so many message boards out there that could contain good OSINT you really need to use message board search engines unless you know about specific message boards that you know your employees use (or could).  Good examples of these are job related message boards like vault.com or Yahoo/Google Finance discussion forums or groups centered around stock trading.</p>
<p>Here is my list of message board search engines and a few that might be more specific for a company:</p>
<p>Google Groups http://groups.google.com/ (always a good choice for creating RSS feeds and very customizable)<br />
Yahoo! Groups http://groups.yahoo.com/<br />
Big Boards http://www.big-boards.com/ (huge list!)<br />
BoardReader http://boardreader.com/ (very good search and RSS feeds of results)<br />
Board Tracker http://boardtracker.com/ (very good search and RSS feeds of results)</p>
<p>More specific:<br />
Craigslist Forums http://www.craigslist.org/about/sites (RSS available)<br />
Vault www.vault.com (job/employee discussions)<br />
Google Finance http://www.google.com/finance (search for company stock symbol and check out the discussions)<br />
XSSed http://www.xssed.com/ (XSS security vulnerabilities)<br />
Full Disclosure Mailing List http://seclists.org/fulldisclosure/ (Security vulnerability disclosure)</p>
<p><strong>Document Repositories</strong><br />
Something that I have seen more of recently are sites called document repositories.  These sites either aggregate documents found from various sources on the Internet or people can upload their own documents and presentations for public sharing purposes.  These sites are probably my favorite since you will find all sorts of interesting information!  Here is my list of favorites:</p>
<p>Docstoc http://www.docstoc.com/<br />
*Really good document search engine.  I wish there was better RSS for it but they have an API in which Yahoo! Pipes could probably be used.</p>
<p>Scribd http://www.scribd.com/ (RSS feed of results)<br />
SlideShare http://www.slideshare.net/ (RSS feed of results)<br />
PDF Search Engine http://www.pdf-search-engine.com/<br />
Toodoc http://www.toodoc.com/</p>
<p><strong>Great! You found documents.  Now what?</strong><br />
Once you find interesting documents be sure to check out the document metadata.  What is metadata? Metadata is simply &#8220;data about data&#8221;.  Metadata in documents is traditionally used for indexing files as well as finding out information about the document creator and what software was used to create the document.  It goes without saying that document metadata is a treasure trove of information that could be used against your company.  For example, vulnerable versions of software that can be used for client side attacks, OS versions, path disclosure, user id&#8217;s and more can all be viewed through document metadata.</p>
<p>There are lots of good tools to pull out metadata from documents and pictures. With some of these tools it&#8217;s even possible to write a script to automatically strip metadata from documents and pictures (start with the script Larry Pesce wrote in his SANS paper below).  However, the best method for removing metadata in my opinion is to make sure it&#8217;s removed (or limited) in the first place!  If you are creating a new document make sure you are removing it or not allowing the application to save some of the more revealing things like user id&#8217;s and OS/version numbers.  If you want more detail on metadata and how to use some of the tools that are available check out the great paper over at the SANS InfoSec Reading Room titled <a href="http://www.sans.org/reading_room/whitepapers/privacy/32974.php">&#8220;Document Metadata, the Silent Killer created by Larry Pesce</a>.  Here is a short list of tools I use (or have used) to analyze metadata:</p>
<p>EXIFtool http://www.sno.phy.queensu.ca/~phil/exiftool/ (my personal favorite! The swiss army knife of metadata tools)<br />
Metagoofil http://www.edge-security.com/metagoofil.php<br />
Maltego (built-in metadata transform) http://www.paterva.com/web4/index.php/maltego (another favorite!)<br />
Meta-Extractor http://meta-extractor.sourceforge.net/<br />
FOCA http://www.informatica64.com/foca/</p>
<p><strong>What&#8217;s the deal with brand reputation?</strong><br />
One last point I want to make is about brand reputation.  You may ask yourself, how does brand reputation relate to information security? Why should we care?  I have found it interesting that many of us in information security have been asked to do more research on brand reputation issues because no one else in the company had those types of skill sets to monitor information.  Brand reputation is vital to an organization, even more so in this economy.  Think of the CIA triad&#8230;Confidentiality, Integrity and Availability.  All three have aspects that reflect brand reputation.  All of us in information security need to be thinking of brand reputation in our daily job.</p>
<p><strong>Next up in part three</strong><br />
In part three I will talk about setting up a simple monitoring program with the sites and tools I have mentioned thus far.  This will include how to start using Yahoo! Pipes to aggregate many of the feeds I talked about.  I will also conclude with information on how to create a Internet Postings Policy or now better known as a Social Media Policy for your company and why this is more important then ever.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2009/10/enterprise-open-source-intelligence-gathering-%e2%80%93-part-2-blogs-message-boards-and-metadata/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Enterprise Open Source Intelligence Gathering &#8211; Part 1 Social Networks</title>
		<link>http://www.spylogic.net/2009/10/enterprise-open-source-intelligence-gathering-part-1-social-networks/</link>
		<comments>http://www.spylogic.net/2009/10/enterprise-open-source-intelligence-gathering-part-1-social-networks/#comments</comments>
		<pubDate>Mon, 26 Oct 2009 19:49:23 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[chrisgates]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[googledorks]]></category>
		<category><![CDATA[informationgathering]]></category>
		<category><![CDATA[linkedin]]></category>
		<category><![CDATA[maltego]]></category>
		<category><![CDATA[myspace]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[socialmedia]]></category>
		<category><![CDATA[socialnetworking]]></category>
		<category><![CDATA[socnetsec]]></category>
		<category><![CDATA[speaking]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.spylogic.net/?p=328</guid>
		<description><![CDATA[UPDATE: You can now download my slide deck from SlideShare. Next week I will be speaking at the 7th Annual Ohio Information Security Summit on &#8220;Enterprise Open Source Intelligence Gathering&#8221;.  Here is the talk abstract: What does the Internet say about your company?  Do you know what is being posted by your employees, customers, or [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-334" title="masked_gather_sm" src="http://www.spylogic.net/wp-content/uploads/2009/10/masked_gather_sm.jpg" alt="masked_gather_sm" width="250" height="139" /><strong>UPDATE:</strong> You can now <a href="http://www.slideshare.net/agent0x0/enterprise-open-source-intelligence-gathering">download my slide deck from SlideShare</a>.</p>
<p>Next week I will be speaking at the<a href="http://informationsecuritysummit.org/"> 7th Annual Ohio Information Security Summit</a> on &#8220;Enterprise Open Source Intelligence Gathering&#8221;.  Here is the talk abstract:</p>
<blockquote><p>What does the Internet say about your company?  Do you know what is being posted by your employees, customers, or your competition?  We all know information or intelligence gathering is one of the most important phases of a penetration test.  However, gathering information and intelligence about your own company is even more valuable and can help an organization proactively determine the information that may damage your brand, reputation and help mitigate leakage of confidential information.</p>
<p>This presentation will cover what the risks are to an organization regarding publicly available open source intelligence.  How can your enterprise put an open source intelligence gathering program in place without additional resources or money.  What free tools are available for gathering intelligence including how to find your company information on social networks and how metadata can expose potential vulnerabilities about your company and applications.  Next, we will explore how to get information you may not want posted about your company removed and how sensitive metadata information you may not be aware of can be removed or limited.   Finally, we will discuss how to build a Internet posting policy for your company and why this is more important then ever.</p></blockquote>
<p>Leading up to my talk at the summit this series of posts will focus on several of the main topics of my presentation.  I plan on referencing these posts during the presentation so attendees can find out more information about a specific topic that will be discussed.  I will touch on the following main points in this series: Part 1 &#8211; Gathering intelligence on social networks, Part 2 &#8211; Gathering intelligence from blogs/message boards/document repositories, Part 3 &#8211; Putting together a simple monitoring program/toolkit and creating a Internet postings (social media) policy for your company.</p>
<p>This first post in the series will focus on gathering intelligence on <strong>social networks</strong>.  The topic of gathering intelligence from social networks will be looked at in two ways.  First, through the eyes of the penetration tester or attacker.  Second, from a monitoring perspective relative to the enterprise and business.</p>
<p><strong>What is OSINT?</strong><br />
<a href="http://en.wikipedia.org/wiki/Open_source_intelligence">Open Source Intelligence</a> (OSINT) is basically finding publicly available information, analyzing it and then using this information for something.  That something can be extremely valuable from the eyes of an attacker.  For a fantastic overview of how OSINT is used specifically from a penetration testing perspective I suggest you check out the <a href="http://www.brucon.org/index.php/Presentations#Open_Source_Information_Gathering">presentation that Chris Gates recently did at BruCON</a>.  Chris goes into detail and provides good examples on how OSINT can be used in gathering intelligence on a network infrastructure as well as how to profile company employees.  All of the techniques Chris talks about should be used in a penetration testing methodology.</p>
<p><strong>Why look for OSINT about your company?</strong><br />
I have found that OSINT is surprisingly often overlooked by most businesses from a security monitoring perspective.  If a company does any monitoring of public information at all it is usually found in your public relations and/or marketing groups.  These groups traditionally don&#8217;t look for things that could be used to target or profile an organization.  The same information that is being viewed by your PR/Marketing department needs to be looked at by your in house information security professionals.  Specifically, I suggest people in your information security department with an &#8220;attacker mindset&#8221; look at this OSINT.  This could be people on an internal penetration testing team or someone involved with the security assessments in your organization.  You should really ask yourself: If you don&#8217;t know what information is publicly available about your company&#8230;how can you properly defend yourself from attack?</p>
<p><strong>OSINT and Social Networks</strong><br />
Social networks have recently become the <a href="http://en-us.nielsen.com/main/news/news_releases/2009/march/social_networks__">4th most popular method for online communication (even ahead of email) today</a>.  If you are not looking for OSINT on social networks you are potentially missing major and vital pieces of information.  Having said that, searching for OSINT on social networks brings its own challenges and needs to be looked at slightly different then looking at other forms of OSINT.  For example, you might find that searching for information on social networks like Facebook different because there is both private and public information.  Facebook as an example has a built in search feature &#8220;behind&#8221; a valid login id and password.  Searching Facebook in this manner can yield better results then just going to Google or using a specific social network search engine (I&#8217;ll talk more about Facebook below).</p>
<p><strong>1. Social Network Search Engines</strong><br />
There are lots of different search engines that specifically look for &#8220;public&#8221; information on some of the major social networks.  The disadvantage about these types of search engines is that they only pull public information that can be easily indexed.  Private information like the Facebook example above cannot be indexed without violating the TOS (Terms of Service) even though there are tools like Maltego that can have transforms written to &#8220;page scrape&#8221; this information (more on that in the Maltego section below). Here is a list of social network search engines that I recommend you check out to search for this type of public information (there are more&#8230;this is just the list I use).  While there are other ways to search specific social networks (like search.twitter.com or FriendFeed) the list below just mentions search engines that search multiple networks:</p>
<p><strong>Wink</strong> http://wink.com/<strong><br />
Spock</strong> http://spock.com (has a search for &#8220;private&#8221; profile info but is a pay service&#8230;haven&#8217;t checked that feature out)<strong><br />
Social Mention</strong> http://socialmention.com/<strong><br />
WhosTalkin </strong>http://www.whostalkin.com/ (this is one of my favorites! Lots of socnets included!)<strong><br />
Samepoint </strong>http://www.samepoint.com/<strong><br />
OneRiot </strong>http://www.oneriot.com/<br />
<strong>Kosmix </strong>http://www.kosmix.com/<br />
<strong>YackTrack</strong> http://www.yacktrack.com<strong><br />
Keotag</strong> http://www.keotag.com/<strong><br />
Twoogle</strong> http://twoogel.com/ (Google/Twitter search combined)<strong><br />
KnowEm Username Check</strong> http://knowem.com/<br />
<strong>Firefox Super Search Add-On</strong> https://addons.mozilla.org/en-US/firefox/addon/13308 (over 160 search engines built in)</p>
<p><strong>Don&#8217;t forget about photo/video social networks and social bookmarking sites:</strong></p>
<p><strong>Pixsy</strong> http://www.pixsy.com/<br />
<strong>Flickr Photo Search</strong> http://www.flickr.com/search/?s=rec&amp;w=all&amp;q=&#8221;comapny name&#8221;&amp;m=text<br />
<strong>YouTube/Google Video Search</strong> http://video.google.com/videosearch?q=&#8221;company name&#8221;<br />
<strong>Junoba Social Bookmark Search</strong> http://www.junoba.com/ (Digg, Delicious, Reddit, etc..)</p>
<p><strong>Pay Services (might be worth checking out):</strong></p>
<p><strong>Filtrbox</strong> http://www.filtrbox.com/<br />
<strong>Vocus</strong> http://www.vocus.com/</p>
<p><strong>2. Maltego</strong><br />
<a href="http://www.paterva.com/web4/index.php/maltego">Maltego</a> goes without saying&#8230;it&#8217;s probably the best tool to &#8220;visually&#8221; show you information found on some of the social networks and the relationships that information has connected to it.  I have found that Maltego works well for Twitter, Facebook, LinkedIn and MySpace profiles (publicly available).  The Twitter transforms are probably the highlight since you can dig into conversations as well.  There is also a Facebook transform that was specifically written to search within the Facebook network using a real user account.  However, this transform doesn&#8217;t work anymore due to recent structural changes to the way Facebook HTML was coded.  Note that this transform violates Facebook TOS since it did screen scraping but when it did work it was a great way to search status and group updates not available to public search engines!  If anyone wants to help get this transform working again there is a <a href="http://www.paterva.com/forum//index.php/topic,138.0.html">thread on the Maltego forum about it</a>.</p>
<p>Lastly, if you want more information on Maltego and how to use it I suggest checking out the work <a href="http://carnal0wnage.attackresearch.com/">Chris Gates</a> has done in his Maltego tutorials <a href="http://www.ethicalhacker.net/content/view/202/24/">here</a> and <a href="http://www.ethicalhacker.net/content/view/251/24/">here</a> to learn more.  Keep in mind.  Maltego works great for finding information if you need it for a specific scope, like a pentest.  Maltego even works great if you need to dig a little deeper into something you find on a social network.  In terms of automating a monitoring process, I suggest using Google dorks, Yahoo Pipes!, and other techniques which we will talk about here and in future posts.</p>
<p><strong>3. Google Dorks (Facebook, MySpace, LinkedIn)</strong><br />
While you can just simply type in your company name into Google and see what comes up&#8230;It&#8217;s way easier to use a little Google dork action to search for information on specific social networks.  As I stated before, this will only pull publicly available information but you might be surprised what you find about your company just in these searches!  Simply paste these into the Google search bar/window.  Note: change &#8220;bank of america&#8221; to whatever you like&#8230;not picking on bofa but there is a ton of information about them on social networks! <img src='http://www.spylogic.net/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p><strong>Facebook Dorks<br />
</strong>Group Search: site:facebook.com inurl:group (bofa | &#8220;bank of america&#8221;)<br />
Group Wall Posts Search: site:facebook.com inurl:wall (bofa | &#8220;bank of america&#8221;)<br />
Pages Search: site:facebook.com inurl:pages (bofa | &#8220;bank of america&#8221;)<br />
Public Profiles: allinurl: people &#8220;John Doe&#8221; site:facebook.com</p>
<p>*To search personal profile status updates (unless they were made public wall posts via pages or groups) you need to be logged into Facebook and use the internal Facebook search engine.  Setting your status updates privacy settings to &#8220;Everyone&#8221; is actually everyone in Facebook.  Rumor has it that next year &#8220;Everyone&#8221; will mean everyone on the Internet! FTW!</p>
<p><strong>MySpace Dorks</strong><br />
Profiles: site:myspace.com inurl:profile (bofa | &#8220;bank of america&#8221;)<br />
Blogs: site:myspace.com inurl:blogs (bofa | &#8220;bank of america&#8221;)<br />
Videos: site:myspace.com inurl:vids (bofa | &#8220;bank of america&#8221;)<br />
Jobs: site:myspace.com inurl:jobs (bofa | &#8220;bank of america&#8221;)</p>
<p><strong>LinkedIn Dorks</strong><br />
Public Profiles: site:linkedin.com inurl:pub (bofa | &#8220;bank of america&#8221;)<br />
Updated Profiles: site:linkedin.com inurl:updates (bofa | &#8220;bank of america&#8221;)<br />
Company Profiles: site:linkedin.com inurl:companies (bofa | &#8220;bank of america&#8221;)</p>
<p>While these are Google dorks from the top three social networks (Twitter actually has a really good search engine, search.twitter.com, which I don&#8217;t think needs explaining), you can easily modify these for your own use and even include more advanced search operators to include or exclude additional queries.  The point of using Google dorks is to make it easier to quickly search for information on social networks without going to each site individually.  Still, with most social networks if you want to find private information you either need to login as a user or use some social engineering get the information you want. <img src='http://www.spylogic.net/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p><strong>What&#8217;s next?</strong><br />
In part three of this series I will talk about how to use Google dorks and various search queries for monitoring purposes.  Once you have the dorks you want to query, it&#8217;s trivial to plug these into Google Alerts to create RSS feeds.  Take your feeds and plug them into your favorite RSS reader and you have a simple monitoring tool.  More on this in part 3 including a section on aggregating this type of into and customizing it via <a href="http://pipes.yahoo.com/pipes/">Yahoo! Pipes</a> which I like to think as the preferred and most customizable method for monitoring social networks.</p>
<p>Next up&#8230;in part 2 I will talk about how to find company information on blogs, message boards and document repositories.  Oh, and sprinkle a little bit of metadata into the mix as well. <img src='http://www.spylogic.net/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2009/10/enterprise-open-source-intelligence-gathering-part-1-social-networks/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Social Zombies: Your Friends Want To Eat Your Brains Video from DEFCON Posted</title>
		<link>http://www.spylogic.net/2009/08/social-zombies-your-friends-want-to-eat-your-brains-video-from-defcon-posted/</link>
		<comments>http://www.spylogic.net/2009/08/social-zombies-your-friends-want-to-eat-your-brains-video-from-defcon-posted/#comments</comments>
		<pubDate>Fri, 28 Aug 2009 13:00:49 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[General Security]]></category>
		<category><![CDATA[bots]]></category>
		<category><![CDATA[defcon]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[kreiosc2]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[myspace]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[socnetsec]]></category>
		<category><![CDATA[speaking]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[vegas]]></category>
		<category><![CDATA[zombies]]></category>

		<guid isPermaLink="false">http://www.spylogic.net/?p=322</guid>
		<description><![CDATA[The video from the talk Kevin Johnson and I did at DEFCON 17 called &#8220;Social Zombies: Your Friends Want To Eat Your Brains&#8221; is now up on Vimeo.  If you missed us at DEFCON Kevin and I will be presenting an updated version at OWASP AppSec DC in November.]]></description>
			<content:encoded><![CDATA[<p>The video from the talk Kevin Johnson and I did at DEFCON 17 called <a href="https://www.defcon.org/html/defcon-17/dc-17-speakers.html#Eston">&#8220;Social Zombies: Your Friends Want To Eat Your Brains&#8221;</a> is now up on <a href="http://vimeo.com/6307559">Vimeo</a>.  If you missed us at DEFCON Kevin and I will be presenting an updated version at <a href="http://www.owasp.org/index.php/Social_Zombies:_Your_Friends_Want_to_Eat_Your_Brains">OWASP AppSec DC in November</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2009/08/social-zombies-your-friends-want-to-eat-your-brains-video-from-defcon-posted/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Old News: Twitter can be used for Botnet Command &amp; Control</title>
		<link>http://www.spylogic.net/2009/08/old-news-twitter-can-be-used-for-botnet-command-control/</link>
		<comments>http://www.spylogic.net/2009/08/old-news-twitter-can-be-used-for-botnet-command-control/#comments</comments>
		<pubDate>Fri, 14 Aug 2009 03:51:10 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[bots]]></category>
		<category><![CDATA[c2]]></category>
		<category><![CDATA[defcon]]></category>
		<category><![CDATA[digininja]]></category>
		<category><![CDATA[kreiosc2]]></category>
		<category><![CDATA[notacon]]></category>
		<category><![CDATA[speaking]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.spylogic.net/?p=318</guid>
		<description><![CDATA[Shocking but true&#8230;today a researcher discovered that Twitter has been used for command and control of a botnet which may have been used by Brazilian hackers to steal online banking login information.  Kudos to the researcher, Jose Nazario, who found this.  It was an interesting read to say the least.  The bot would basically look [...]]]></description>
			<content:encoded><![CDATA[<p>Shocking but true&#8230;today a researcher discovered that <a href="http://asert.arbornetworks.com/2009/08/twitter-based-botnet-command-channel/">Twitter has been used for command and control of a botnet</a> which may have been used by Brazilian hackers to steal online banking login information.  Kudos to the researcher, Jose Nazario, who found this.  It was an interesting read to say the least.  The bot would basically look for base64 encoded commands on a Twitter account to download malware via RSS feeds with obfuscated (shortened) URL&#8217;s.  Interesting&#8230;sounds a lot like <a href="http://www.digininja.org/projects/kreiosc2.php">Robin Wood&#8217;s tool KreiosC2 which was released at DEFCON 17</a>.  I even did <a href="http://www.youtube.com/watch?v=2xLierFGOhQ">this demo</a> showing what else? Base64 encoded commands.  Ironically, <a href="http://www.spylogic.net/2009/04/social-network-bots-presentation-and-my-recap-from-notacon-6/">I showed off the first version of this code at Notacon 6 back in April of this year</a>.  Keep in mind, KreiosC2 can be used for legitimate tasks like controlling things at home remotely via Twitter.  I highly recommend you read <a href="http://www.digininja.org/projects/kreiosc2.php">Robin&#8217;s detailed write-up</a> on how KreiosC2 functions.</p>
<p>What I find fascinating (like most things in security) is that now that there has been a real confirmed case of using Twitter for botnet C2 (Command &amp; Control) the media seems to be jumping on it and even <a href="http://www.wired.com/threatlevel/2009/08/botnet-tweets/">trying to determine &#8220;why it took so long for hackers to take Twitter to the dark side&#8221;</a>.  Well, you can&#8217;t say we didn&#8217;t warn you.</p>
<p>The point that Robin, myself and others were trying to make way back in April was that this is a real threat and the bad guys have probably started to use Twitter for C2 even before Robin put out the code!  We were hoping that by releasing the code Twitter (and others) would see this as perhaps an early warning of things to come and perhaps prepare some defense for it (yes, we know it&#8217;s hard to put a defense together for something like this).  Now that we have a confirmed case used for malicious purposes we hope Twitter takes this seriously and can combat future C2 channels used for very bad things.  It always takes something bad to happen to create change&#8230;where have you heard that before? <img src='http://www.spylogic.net/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2009/08/old-news-twitter-can-be-used-for-botnet-command-control/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Social Zombies Slides and DEFCON Updates</title>
		<link>http://www.spylogic.net/2009/08/social-zombies-slides-and-defcon-updates/</link>
		<comments>http://www.spylogic.net/2009/08/social-zombies-slides-and-defcon-updates/#comments</comments>
		<pubDate>Thu, 06 Aug 2009 13:00:08 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[bots]]></category>
		<category><![CDATA[defcon]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[kreiosc2]]></category>
		<category><![CDATA[myspace]]></category>
		<category><![CDATA[socnetsec]]></category>
		<category><![CDATA[speaking]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[vegas]]></category>
		<category><![CDATA[zombies]]></category>

		<guid isPermaLink="false">http://www.spylogic.net/?p=311</guid>
		<description><![CDATA[Kevin and I want to thank everyone that came out to our talk at DEFCON 17 this past weekend.  We had a great time giving the talk and thanks for the feedback!  Even the two Facebook developers that came to our Q&#38;A enjoyed it!  Having said that, Kevin and I will never, ever get a [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.spylogic.net/wp-content/uploads/2009/08/tom_kevin_zombie.jpg"><img class="alignright size-thumbnail wp-image-312" title="tom_kevin_zombie" src="http://www.spylogic.net/wp-content/uploads/2009/08/tom_kevin_zombie-150x150.jpg" alt="tom_kevin_zombie" width="150" height="150" /></a>Kevin and I want to thank everyone that came out to <a href="https://www.defcon.org/html/defcon-17/dc-17-speakers.html#Eston">our talk at DEFCON 17</a> this past weekend.  We had a great time giving the talk and thanks for the feedback!  Even the two Facebook developers that came to our Q&amp;A enjoyed it!  Having said that, Kevin and I will <strong>never</strong>, <strong>ever</strong> get a <a href="http://www.flickr.com/photos/dualcoremusic/3792689097/in/photostream/">Facebook party</a> invite while at Black Hat and/or DEFCON.  Oh well! At least <a href="http://twitter.com/dualcoremusic">@dualcoremusi</a>c got to play live! <img src='http://www.spylogic.net/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>You can <a href="http://www.slideshare.net/agent0x0/social-zombies-your-friends-want-to-eat-your-brains">download the slide deck from SlideShare</a> that was in the DEFCON 17 CD.  We plan on giving the talk a few more times in the next few months so we don&#8217;t plan to release the full version of the slide deck yet.  However, we will post the video as soon as we get it.  The slides on the DEFCON CD are mostly text&#8230;no cool Zombie graphics (thanks to <a href="http://twitter.com/JaneDelay">@JaneDelay</a> for the Photoshop work BTW) but it should give you a good overview of the talk.</p>
<p><a href="http://www.digininja.org/projects/kreiosc2.php">Robin Wood&#8217;s fantastic tool called KreiosC2</a> was also released during our talk.  <a href="http://www.youtube.com/watch?v=2xLierFGOhQ">I did a demo which is posted here</a> and talked a lot about how the PoC code functions.  If you don&#8217;t know already&#8230;KreiosC2 is a tool written in Ruby which allows IRC like command and control of systems over Twitter.  Very cool!  Also, check out the <a href="http://www.digininja.org/">redesign</a> of Robin&#8217;s website.  Awesome.  Make sure you <a href="https://twitter.com/digininja">follow Robin on Twitter</a>!  He is one you need to follow!</p>
<p>DEFCON was awesome as usual!  Lot&#8217;s of people this year..perhaps an increase from last year and of course the <a href="http://gizmodo.com/5330555/warning-not-all-atms-at-defcon-are-what-they-appear-to-be">usual hijinks</a>.  It was awesome catching up with everyone and meeting new people.  I attended lots of great talks including the &#8220;<a href="https://www.defcon.org/html/defcon-17/dc-17-speakers.html#Mortman">DEFCON Security Jam 2: The Fails Keep on Coming</a>&#8220;.  This was one that you should see the video for&#8230;especially the presentations by <a href="http://twitter.com/haxorthematrix">@haxorthematrix</a> and @myrcurial.  Speaking of @mycurial&#8230;you really need to see the awesome yet scary presentation that <a href="http://twitter.com/myrcurial">@myrcurial</a> and <a href="http://twitter.com/TiffanyRad">@TiffanyRad</a> did on Sunday titled &#8220;<a href="https://www.defcon.org/html/defcon-17/dc-17-speakers.html#Myrcurial2">Your Mind: Legal Status, Rights and Securing Yourself</a>&#8220;.  I highly recommend this talk!</p>
<p>The podcasters meetup was also a success!  Thanks to <a href="http://twitter.com/pauldotcom">@pauldotcom</a> for hosting and for throwing such an awesome party this year and a shout out to the guys over at <a href="http://i-hacked.com/">I-Hacked.com</a>!  The audio will be posted soon, probably over at the <a href="http://securityjustice.com">Security Justice</a> site.</p>
<p>Pictures will be posted soon!  Still trying to recover from Vegas!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2009/08/social-zombies-slides-and-defcon-updates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Launching: SocialMediaSecurity.com</title>
		<link>http://www.spylogic.net/2009/07/launching-socialmediasecurity-com/</link>
		<comments>http://www.spylogic.net/2009/07/launching-socialmediasecurity-com/#comments</comments>
		<pubDate>Wed, 29 Jul 2009 20:45:31 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[defcon]]></category>
		<category><![CDATA[Privacy on the Internetz]]></category>
		<category><![CDATA[socialmedia]]></category>
		<category><![CDATA[socialnetworking]]></category>
		<category><![CDATA[socnetsec]]></category>

		<guid isPermaLink="false">http://www.spylogic.net/?p=305</guid>
		<description><![CDATA[I wanted to get this post up before I leave for DefCon since it will be hard to have time to blog in Vegas.  In a nutshell, I started a new web site called socialmediasecurity.com.  This was originally a project that I started to move my social media research over to a separate web site [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-306" title="skull" src="http://www.spylogic.net/wp-content/uploads/2009/07/skull.jpg" alt="skull" width="104" height="102" />I wanted to get this post up before I leave for DefCon since it will be hard to have time to blog in Vegas.  In a nutshell, I started a new web site called <a href="http://socialmediasecurity.com">socialmediasecurity.com</a>.  This was originally a project that I started to move my social media research over to a separate web site but has since evolved into something much larger.  What I have done is consolidated (with permission) research from other security researchers such as Aviv Raff, Joseph Bonneau, Kevin Johnson, Nathan Hamiel, Scott Wright, theharmonyguy and more.  Each article links back to the original author.  The purpose of this was to have an easy way to search on a specific topic or social network (for example: Twitter) and get the security information you are looking for.  You can subscribe to post updates via <a href="http://feeds.feedburner.com/socialmediasecurity">RSS</a>, <a href="http://feedburner.google.com/fb/a/mailverify?uri=SocialMediaSecurity&amp;loc=en_US">Email</a> or through <a href="http://www.twitter.com/socialmediasec">Twitter</a>.</p>
<p>In addition, at the top of the page are links to downloadable guides, presentations, video&#8217;s and more.  All of this content is related to user education and awareness on social media security issues.  This is obviously a work in progress and I plan to have more content added to this very soon.  One thing I am working on that I wanted to get out before my talk at DefCon was a detailed walk-through video of the Facebook Privacy Settings (basically a walk-through of my guide).  I haven&#8217;t finished the video yet and I might have to redo it since Facebook will be releasing a new interface for privacy settings in the near future.  The plan is to do one for each of the major social networking sites as well as a downloadable guide like the Facebook one.</p>
<p>So&#8230;you can also concider this a call for volunteers! <img src='http://www.spylogic.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />   If you would like to contribute anything (guides, videos, research, tools, blog on the site) or have feedback let me know by sending me an email (tom[aT]spylogic.net).  There are a few other researchers and volunteers working on some really cool stuff for the web site.  Far too many ignore the security and privacy issues of social media.  We welcome your participation to help make a difference!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2009/07/launching-socialmediasecurity-com/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Another Twitter Scam: Twitviewer</title>
		<link>http://www.spylogic.net/2009/07/another-twitter-scam-twitviewer/</link>
		<comments>http://www.spylogic.net/2009/07/another-twitter-scam-twitviewer/#comments</comments>
		<pubDate>Tue, 28 Jul 2009 20:16:29 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[socnetsec]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.spylogic.net/?p=299</guid>
		<description><![CDATA[One of the trending topics today on Twitter was &#8220;Twitviewer&#8221; becuase of a site called Twitviewer[d0t]net which asks visitors to enter in your Twitter user id and password to find out who is &#8220;stalking&#8221; you.  When you do, you get a sample of people on Twitter that are not even following you as stated in [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.spylogic.net/wp-content/uploads/2009/07/twitviewer.jpg"><img class="size-thumbnail wp-image-301 alignright" title="twitviewer" src="http://www.spylogic.net/wp-content/uploads/2009/07/twitviewer-150x150.jpg" alt="twitviewer" width="150" height="150" /></a>One of the trending topics today on Twitter was &#8220;Twitviewer&#8221; becuase of a site called Twitviewer[d0t]net which asks visitors to enter in your Twitter user id and password to find out who is &#8220;stalking&#8221; you.  When you do, you get a sample of people on Twitter that are not even following you <a href="http://mashable.com/2009/07/28/twitviewer/">as stated in this Mashable post</a>.  The app also sends out a tweet using your credentials stating: &#8220;<span>Want to know whos stalking you on twitter!?: hxxp://TwitViewer[d0t]net&#8221;.  If you did fall victim to this you better change your password ASAP!  Check out the screenshot of the site before it was taken down&#8230;yeah, phishy indeed.</span></p>
<p><span>Who knows what the developers of this application were planning (malicious or others).  Regardless, you should never give a third party site (especially ones that look phishy like this one) your Twitter credentials.  In fact, I recommend you only use third party Twitter sites that use <a href="http://apiwiki.twitter.com/OAuth-FAQ">OAuth</a> for authenticating you to Twitter.  That way you don&#8217;t have to give your credentials to the web site and worry about them being compromised.  Also, look to see what the purpose of the site is before you give the jewels away&#8230;if it&#8217;s a way to see who&#8217;s following you, enter credentials to get millions of followers, etc&#8230;then it&#8217;s probably a scam or <a href="http://uk.techcrunch.com/2009/01/13/and-todays-useless-but-funny-twitter-app-is-twicksize/">just completely useless</a>. </span></p>
<p><span>Think about this.  If the developer of a site like this wanted to they could easily use your captured Twitter credentials and start trying them on other social networks and/or web mail services.  They can then use these credentials for anything else they wanted.  Unfortunatly, most users of these sites use the same password for everything.  Again, this is a reminder to use a password manager if you are one of those that use the same user id/password for everything.  See <a href="http://www.spylogic.net/2008/12/who-are-you-giving-your-twitter-account-to/">this article for more information on password managers and social media web sites</a>.<br />
</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2009/07/another-twitter-scam-twitviewer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Social Zombies Invade Las Vegas!</title>
		<link>http://www.spylogic.net/2009/07/social-zombies-invade-las-vegas/</link>
		<comments>http://www.spylogic.net/2009/07/social-zombies-invade-las-vegas/#comments</comments>
		<pubDate>Tue, 21 Jul 2009 14:00:28 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[bots]]></category>
		<category><![CDATA[defcon]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[myspace]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[socnetsec]]></category>
		<category><![CDATA[speaking]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[vegas]]></category>
		<category><![CDATA[zombies]]></category>

		<guid isPermaLink="false">http://www.spylogic.net/?p=293</guid>
		<description><![CDATA[Yes, you are reading the title of this post correctly!  Massive Zombie attacks at DefCon this year&#8230;bring your shotgun (we are kidding of course, please do not bring firearms to DefCon&#8230;you will make the goons very unhappy)!  Seriously though, Kevin Johnson and I will be presenting &#8220;Social Zombies: Your Friends Want to Eat Your Brains&#8221; [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-294" title="zombie" src="http://www.spylogic.net/wp-content/uploads/2009/07/zombie-300x200.jpg" alt="zombie" width="300" height="200" />Yes, you are reading the title of this post correctly!  Massive Zombie attacks at DefCon this year&#8230;bring your shotgun (we are kidding of course, please do not bring firearms to DefCon&#8230;you will make the goons very unhappy)!  Seriously though, Kevin Johnson and I will be presenting <a href="https://www.defcon.org/html/defcon-17/dc-17-speakers.html#Eston">&#8220;Social Zombies: Your Friends Want to Eat Your Brains&#8221; </a>at <a href="https://www.defcon.org/">DefCon 17</a> in Las Vegas on <strong>Sunday, August 2nd at 4pm. </strong></p>
<p>My part of the talk is focused on security and privacy concerns with social networks, fake accounts, using social networks for penetration testing and the proliferation of bots on social networks.  I will also be talking about a new version of <a href="http://www.digininja.org/">Robin Wood&#8217;s fantastic &#8220;Twitterbot&#8221;</a> (we actually have a new name for the tool which will be announced at DefCon).  I&#8217;ll be providing a live demo showing the new and improved features of his tool!  Big shoutout to <a href="http://twitter.com/digininja">Robin</a> for all the work he did on this tool!</p>
<p>The other speaker is <a href="http://twitter.com/secureideas">Kevin Johnson</a> who you may know as the project lead for <a href="http://base.secureideas.net/">BASE</a> and <a href="http://samurai.inguardians.com/">SamuraiWTF</a> (Web Testing Framework).  Kevin is also a SANS instructor for <a href="http://www.sans.org/training/description.php?mid=942">Security 542</a> (Web App Penetration Testing and Ethical Hacking).  When he isnt managing projects and teaching he&#8217;s most likely <span style="text-decoration: line-through;">abusing</span> &#8220;playing with&#8221; social networks.  Kevin will be talking about SocialButterfly which is an application that can leverage and exploit various social network API&#8217;s.  He will also talk about manipulating social networks (and thier users) with third-party applications.  Remember: please accept any and all &#8220;friend requests&#8221; from Kevin Johnson! <img src='http://www.spylogic.net/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>From our talk abstract:</p>
<blockquote><p>In Social Zombies: Your Friends want to eat Your Brains, Tom Eston and Kevin Johnson explore the various concerns related to malware delivery through social network sites. Ignoring the FUD and confusion being sowed today, this presentation will examine the risks and then present tools that can be used to exploit these issues.</p>
<p>This presentation begins by discussing how social networks work and the various privacy and security concerns that are caused by the trust mass that is social networks. We use this privacy confusion to exploit members and their companies during our penetration tests.</p>
<p>The presentation then discusses typical botnets and bot programs. Both the delivery of this malware through social networks and the use of these social networks as command and control channels will be examined.</p>
<p>Tom and Kevin next explore the use of browser-based bots and their delivery through custom social network applications and content. This research expands upon previous work by researchers such as Wade Alcorn and GNUCitizen and takes it into new C&amp;C directions.</p>
<p>Finally, the information available through the social network APIs is explored using the bot delivery applications. This allows for complete coverage of the targets and their information.</p></blockquote>
<p>How did this talk come together?  Kevin and I had some past converations regarding social network bots (mostly from <a href="http://www.spylogic.net/2009/04/social-network-bots-presentation-and-my-recap-from-notacon-6/">my Notacon 6 talk</a>) and decided that much of our research was similar so it made sense to &#8220;combine forces&#8221; to work on some of this research together.  Also, by working on bots and socnet bot delivery mechinisms we hope to raise awareness about some of the security and privacy threats that are out there, not just for the users of social networks.  Oh, and we both like Zombies.  See you at DefCon!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2009/07/social-zombies-invade-las-vegas/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Spylogic.net Reloaded</title>
		<link>http://www.spylogic.net/2009/07/spylogic-net-reloaded/</link>
		<comments>http://www.spylogic.net/2009/07/spylogic-net-reloaded/#comments</comments>
		<pubDate>Wed, 15 Jul 2009 03:27:28 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Spylogic News]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[migration]]></category>
		<category><![CDATA[nucleuscms]]></category>
		<category><![CDATA[spylogic]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.spylogic.net/?p=287</guid>
		<description><![CDATA[You may have noticed something strange about my blog.  Clean, smooth, fast, different&#8230;these are all things that describe the look and feel of the new blog (hopefully).  What happened?  Well for starters I was fed up with the basic features of Nucleus CMS.  While Nucleus was a very stable and reliable (read: low on the [...]]]></description>
			<content:encoded><![CDATA[<p>You may have noticed something strange about my blog.  Clean, smooth, fast, different&#8230;these are all things that describe the look and feel of the new blog (hopefully).  What happened?  Well for starters I was fed up with the basic features of Nucleus CMS.  While Nucleus was a very stable and reliable (read: low on the blog hacking list), it&#8217;s about ten years behind in blogging technology.  No built in post tagging, no WYSIWYG editor, link lists that had to be edited in php, etc&#8230;I picked WordPress to upgrade to because it&#8217;s really the most user friendly and has some really great features and plugins.  Yeah, it&#8217;s a target for vulnerabilities but I&#8217;m willing to live with that as long as I have a blog that&#8217;s easy to maintain and can help me save time when posting/editing things.</p>
<p><strong>The adventure of blog migration to WordPress</strong><br />
I started the transition from Nucleus CMS to WordPress early last week&#8230;of course thinking this would be an easy migration.  Ummm, no.  It was pretty painful actually.  You see, WordPress doesn&#8217;t have a official migration path from Nucleus CMS.  So I had to rely on the advice of others in the WordPress community that had done the same upgrade in the past.  Of course there were a bunch of different ways to do this so I basically took a few of the migration scripts that a few others have written, hacked them up even more and tested.  Testing took about a week&#8230;it really sucked.  I had to install version 2.1 of WordPress to use a certain migration script that I didn&#8217;t feel like recoding to get to work with 2.8.1.  Of course my categories and images were FUBAR so there was another script I had to write to fix that.  BUT, the biggest issue was how Nucleus handles URL&#8217;s for blog posts.  The problem was that I had lots of links out there in Google and other places pointing to blog posts.  In Nucleus my post links were like this:</p>
<blockquote><p>http://spylogic.net/item/438</p></blockquote>
<p>WordPress links are something like this:</p>
<blockquote><p>http://spylogic.net/2009/07/password-length-and-complexity-for-social-media-sites/</p></blockquote>
<p>So your probably thinking that I can just make my links in WordPress match the Nucleus links?  Nope.  WordPress renumbered all my posts out of order and writing another script to re-number 400+ posts wasn&#8217;t in my plan.  So&#8230;<a href="http://httpd.apache.org/docs/1.3/mod/mod_rewrite.html">mod_rewrite</a> and php scripting to the rescue!  I must say, I haven&#8217;t had a situation yet where I had to manipulate URL&#8217;s on a website yet but now that I did&#8230;mod_rewrite is awesome and it was a great learning experience.  I won&#8217;t go into gory detail but in a nutshell I used a SQL query to map my old numbered posts from the nucleus posts table to the WordPress style URL naming&#8230;by date so they match up.  I then took that query output and put it into a php script.  The php script is referenced in my .htaccess file that contains the RewriteRules.  So&#8230;when someone clicks on the old style Nucleus links the script maps it to the new links.  Cool.  If you want to see all of the code <a href="http://budts.be/weblog/2009/01/convert-a-nucleus-blog-to-wordpress/">I followed the guide that another blogger</a> posted about his migration but made my own modifications and did a few things different then his code did&#8230;but you should get the general idea.</p>
<p><strong>What changes?</strong><br />
So besides the blogging platform other things I decided to do was a new logo/header that <a href="http://twitter/JaneDeLay">@JaneDeLay</a> created for me (she rocks!) and I decided to include more of my <a href="http://www.spylogic.net/publications/">other publications, articles and such</a> in separate pages.  I also put a <a href="http://www.spylogic.net/speaking/">speaking</a> page where you can find out where I&#8217;m speaking at and also a list of past talks (something a few of you have wanted to know).  RSS feeds are still through FeedBurner so you don&#8217;t have to update your feeds.  Lastly, I decided to move the majority of my social media security research to another site altogether.  This site is focused on social media security and will have guides, videos, presentations and research from not only myself but others.  I&#8217;m planning on launching the site at DEFCON 17 at my talk or right before it.  It&#8217;s been difficult blogging about anything lately because of my crazy work/home/life schedule so hopefully the new site will bring some focus back into blogging and about other things besides social media. <img src='http://www.spylogic.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  I&#8217;ll probably mention some of the content from the new site on this blog if it seems relevant.</p>
<p>Anyway, let me know if you have any feedback on the new site (there might be a few bugs still) and thanks for reading my blog!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2009/07/spylogic-net-reloaded/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Password Length and Complexity for Social Media Sites</title>
		<link>http://www.spylogic.net/2009/07/password-length-and-complexity-for-social-media-sites/</link>
		<comments>http://www.spylogic.net/2009/07/password-length-and-complexity-for-social-media-sites/#comments</comments>
		<pubDate>Thu, 02 Jul 2009 22:33:55 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[keepass]]></category>
		<category><![CDATA[linkedin]]></category>
		<category><![CDATA[myspace]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[socnetsec]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[youtube]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[July 1st was &#8220;Twittersec&#8221; day as coined by @hevnsnt over at I-Hacked.com to designate July 1st as change your Twitter password day. Why? Mostly because July is the &#8220;month of Twitter bugs&#8221; created by a security researcher in which he will announce a bug in a &#8220;3rd party Twitter application&#8221; everyday for the month of [...]]]></description>
			<content:encoded><![CDATA[<p>July 1st was &#8220;Twittersec&#8221; day as coined by <a href="http://twitter.com/hevnsnt">@hevnsnt</a> over at <a href="http://www.i-hacked.com/">I-Hacked.com</a> to designate July 1st as change your Twitter password day.  Why? Mostly because July is the &#8220;month of Twitter bugs&#8221; created by a security researcher in which <a href="http://twitpwn.com/">he will announce a bug in a &#8220;3rd party Twitter application&#8221;</a> everyday for the month of July to raise awareness on security issues with the Twitter API.  Technically, this should be &#8220;month of 3rd party&#8221; Twitter bugs but whatever.  Either way it will raise awareness about some of the security issues of Twitter and 3rd party applications.</p>
<p>ANYWAY, back to my point&#8230;.I sent out some tweets about changing your Twitter password and now being a good time to use a password manager like <a href="http://keepass.info">Keepass</a> to manage multiple, complex passwords for everything&#8230;not just social media sites.  One problem though is that each site might have different password length and complexity requirements.  This becomes an annoying issue when you choose a randomly generated password like I suggest when using a password manager.  You will encounter many sites that have specific requirements and others that do not.  Obviously, the longer and more complex the password is the harder it is to crack so I suggest going as long as you can.  Sad that there are these limitations on certain sites (blame the site developers) but if you set your random password generator to a very large number (I recommend at least 20 with a mix of everything you can throw at it including white spaces if the site will let you), it&#8217;s as good as your going to get.</p>
<p>Keep in mind, some applications even supported by the site (like the Facebook app for BlackBerry and iPhone) might not like passwords over a certain length or even certain special characters&#8230;you will know once you use these apps.  Also, I mention Keepass as a password manager because you can use it on a BlackBerry or Windows Mobile device as well&#8230;an iPhone version is being worked on.  So here you go&#8230;max password lengths for the major social media sites:</p>
<p><strong>Twitter</strong><br />
None. I tried a 500 character password with everything but white spaces and it worked.</p>
<p><strong>Facebook</strong><br />
None. I tried a 1000 character password with everything but white spaces and it worked.</p>
<p><strong>MySpace</strong><br />
10 characters! Wow&#8230;really bad.  Now I know another reason MySpace sucks.</p>
<p><strong>LinkedIn</strong><br />
16 characters! This is interesting.  LinkedIn truncates the password to 16 characters! Even if you put in a password larger then 16 characters it will only use the first 16, you can actually see this when entering in a password. No user notification, no info about this in the &#8216;help&#8217; section.  Sneaky and evil.</p>
<p><strong>YouTube</strong><br />
None.  Your account is tied to your Google account so is kind of a pain to change&#8230;but I didn&#8217;t find any issues with length or complexity.</p>
<p>On another note&#8230;I wonder if Twitter and Facebook truncate the passwords at a certain length and don&#8217;t tell you?  Not sure&#8230;but it would be interesting to find out.  This is another bad design as a they could easily just hash the entire password (which is a certain manageable length) and the hash is stored in the database not the large character password.  Does this mean that sites like MySpace and LinkedIn are storing passwords in clear text?  Also, I have run into other sites (non-social network) that actually truncate the password because when you try to login with an overly complex password&#8230;you get denied!  Then you enter the cycle of doom&#8230;resetting your password thinking you fat fingered that password to begin with over and over. :-/</p>
<p><strong>Are social media password limitations working against you?</strong><br />
Finally, just a quick point on this.  Social media sites like MySpace and LinkedIn should NEVER have any limitations on password length or complexity.  Certain complexity restrictions (like white space or strange characters) I could understand since you would have to use these passwords on mobile devices and other integrated apps.  However, there are no technical limitations of just hashing the passwords to a constant length&#8230;and we all know storing passwords in a database in clear text is never a good thing.</p>
<p>Shouldn&#8217;t these social media sites that you already give your personal information to be trying to protect you the user as best as they can by letting you set a long and complex password?  Let&#8217;s hope MySpace and LinkedIn get better at this real soon!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2009/07/password-length-and-complexity-for-social-media-sites/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Establishing your social media presence with security in mind</title>
		<link>http://www.spylogic.net/2009/06/establishing-your-social-media-presence-with-security-in-mind/</link>
		<comments>http://www.spylogic.net/2009/06/establishing-your-social-media-presence-with-security-in-mind/#comments</comments>
		<pubDate>Mon, 01 Jun 2009 23:51:41 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[articles]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[linkedin]]></category>
		<category><![CDATA[socialnetworking]]></category>
		<category><![CDATA[socnetsec]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[If you have been using social media or are curious of the security of this emerging technology you may be interesting reading my recently published article in issue 21 of (IN)SECURE Magazine. In my article I discuss why companies are starting to use social media, the benefits/risks and what information may be posted about your [...]]]></description>
			<content:encoded><![CDATA[<p>If you have been using social media or are curious of the security of this emerging technology you may be interesting reading my <a href="http://www.net-security.org/dl/insecure/INSECURE-Mag-21.pdf">recently published article in issue 21 of (IN)SECURE Magazine</a>.  In my article I discuss why companies are starting to use social media, the benefits/risks and what information may be posted about your company on social media/networking web sites.  I also talk about some cost effective tools your company can use to start your own social media monitoring program (without spending a ton of cash) and how to put in place guidelines for employees regarding the use of social media. Yes, even if you block these sites in the workplace employees are going to use social media/network sites outside of work if you like it or not&#8230;you had better get used to it and adapt your policies!</p>
<p>This article started from me actually seeing how much information there is about businesses within social networks.  Both good and bad!  The information I have found has been extremely valuable when conducting penetration tests.  In fact, this information can be so valuable that you may be surprised how easy it is to use this information for social engineering or more&#8230;the possibilities are endless.  As I pointed out in my article, get together with the business leaders in your marketing and/or public relations group and talk about social media and how to use it with a bit of security and privacy in mind.  You might be surprised how receptive they are to the input from a security professional!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2009/06/establishing-your-social-media-presence-with-security-in-mind/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Links from my NEOISF Talk: New School Man-In-The-Middle</title>
		<link>http://www.spylogic.net/2009/05/links-from-my-neoisf-talk-new-school-man-in-the-middle/</link>
		<comments>http://www.spylogic.net/2009/05/links-from-my-neoisf-talk-new-school-man-in-the-middle/#comments</comments>
		<pubDate>Wed, 20 May 2009 20:00:00 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[arpon]]></category>
		<category><![CDATA[arpwatch]]></category>
		<category><![CDATA[cain]]></category>
		<category><![CDATA[ettercap]]></category>
		<category><![CDATA[middler]]></category>
		<category><![CDATA[mitm]]></category>
		<category><![CDATA[NEOISF]]></category>
		<category><![CDATA[networkminer]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[speaking]]></category>
		<category><![CDATA[sslstrip]]></category>
		<category><![CDATA[wireshark]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Here are the links for the tools from my talk titled &#8220;New School Man-In-The-Middle&#8221; that was given at the North East Ohio Information Security Forum (NEOISF). I will update this post with a link to the slide deck on SlideShare by the end of the week. Thanks to everyone for coming out! Old School! Wireshark [...]]]></description>
			<content:encoded><![CDATA[<p>Here are the links for the tools from my talk titled &#8220;New School Man-In-The-Middle&#8221; that was given at the North East Ohio Information Security Forum (NEOISF).  I will update this post with a link to the slide deck on SlideShare by the end of the week.  Thanks to everyone for coming out!</p>
<p><strong>Old School!</strong><br />
<a href="http://www.wireshark.org">Wireshark </a><br />
<a href="http://ettercap.sourceforge.net">Ettercap</a><br />
<a href="http://www.oxid.it/cain.html">Cain </a></p>
<p><strong>New School!</strong><br />
<a href="http://networkminer.sourceforge.net">Network Miner</a><br />
<a href="http://code.google.com/p/middler/">The Middler</a><br />
<a href="http://www.thoughtcrime.org/software/sslstrip/">SSLStrip</a></p>
<p>* Note: &#8230;both the new and old school tools provide the pentester with a ton of value! Use them all!</p>
<p><strong>MITM Defense</strong><br />
<a href="http://arpon.sourceforge.net/">ArpON</a><br />
<a href="http://www-nrg.ee.lbl.gov">ArpWatch</a></p>
<p><strong>UPDATE:</strong> <a href="http://www.slideshare.net/agent0x0/new-school-maninthemiddle">Click here to view the slide deck.</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2009/05/links-from-my-neoisf-talk-new-school-man-in-the-middle/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Potential dangers of BlackBerry Syncing Applications</title>
		<link>http://www.spylogic.net/2009/05/potential-dangers-of-blackberry-syncing-applications/</link>
		<comments>http://www.spylogic.net/2009/05/potential-dangers-of-blackberry-syncing-applications/#comments</comments>
		<pubDate>Tue, 05 May 2009 04:59:06 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[blackberry]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[mobile]]></category>
		<category><![CDATA[socnetsec]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Do you have a BlackBerry for work and you have a corporate policy pushed down and managed by your corporate IT team? Depending on how locked down the policy is for your corporate BlackBerry deployment you may be syncing sensitive or confidential data to a public web site. So I recently installed the Facebook Blackberry [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://spylogic.net/media/4/20090505-blackberry_sync.gif" alt="Syncing dangers?" /><br />
<br />
Do you have a BlackBerry for work and you have a corporate policy pushed down and managed by your corporate IT team?  Depending on how locked down the policy is for your corporate BlackBerry deployment you may be syncing sensitive or confidential data to a public web site.  </p>
<p>So I recently installed the <a href="http://www.allfacebook.com/2009/04/new-facebook-for-blackberry-launches/">Facebook Blackberry Application v1.5</a> on my BlackBerry and noticed two interesting settings.  First, you can sync your Facebook calendar with your BlackBerry calendar.  Second, you can sync your Facebook contacts with your BlackBerry contacts.  As far as I can tell syncing is only one way&#8230;sort of.  The Facebook application has a disclaimer when you install the application that says:</p>
<p><b>Facebook will &#8220;periodically send copies of your BlackBerry device Contacts to Facebook Inc. to match and connect with your Facebook Friends.&#8221;</b></p>
<p>So does this mean Facebook has a copy of your corporate contacts?  They must somewhere to do the proper sync matching.  There is another disclaimer at the bottom of the &#8220;setup wizard&#8221; that says you allow Facebook to do this interaction per the same way applications have access to your profile data in Facebook.  Interesting.  Again, not a nightmare situation&#8230;but if any of your business contacts are sensitive in nature I would be hesitant to enable this feature.  Worse case?  I couldn&#8217;t think of a worse security nightmare then of all your users automatically sending sensitive calendar entries with proprietary data to Facebook!  So yeah, one way is good.  For now one way sync is all the Facebook application does but I would be willing to bet that this will change in the future.  Be careful with this one.</p>
<p>So lets step this up a bit.  What about two way syncing applications like <a href="http://www.google.com/mobile/blackberry/sync.html">Google Sync</a>?  Google Sync will sync your Google Calendar/Contacts with your Blackberry Calendar/Contacts&#8230;both ways!  This might be a real problem if you make your Google Calendar public or share it with a group of friends.  Same goes for your business contacts. You may have just given Google (and possibly the world) all your business calendar entries.  Well..we know Google isn&#8217;t evil, right? :-/</p>
<p>What can we do about this?  As a user&#8230;opt out of installing any syncing apps on your corporate BlackBerry for starters.  But what about blocking syncing on the device via BES policy?  As far as I can tell the only way is to block the application from being installed via policy.  This will become problematic when Google/Facebook releases new versions for example.  Not sustainable.  I&#8217;m no BES administrator but there might be other ways to prevent the application from being installed or the syncing from happening but it brings up some interesting discussion.  By the way, there are some problems when you have the <a href="http://forums.crackberry.com/f83/facebook-1-5-calendar-sync-207163/">Facebook application and Google Sync installed at the same time</a>.  No thanks.</p>
<p>Something else to think about.  How does your company handle BlackBerry deployments?  Are they company issued and owned?  Or do you allow your users to own them and the company pays for the data plan?  All of this would have to be considered before blocking or preventing syncing applications (or any third-party application) from being installed.  If you have any thoughts or ideas on this, comment below!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2009/05/potential-dangers-of-blackberry-syncing-applications/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Social Network Bots Presentation and my Recap from Notacon 6</title>
		<link>http://www.spylogic.net/2009/04/social-network-bots-presentation-and-my-recap-from-notacon-6/</link>
		<comments>http://www.spylogic.net/2009/04/social-network-bots-presentation-and-my-recap-from-notacon-6/#comments</comments>
		<pubDate>Tue, 21 Apr 2009 04:43:01 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[bots]]></category>
		<category><![CDATA[notacon]]></category>
		<category><![CDATA[socnetsec]]></category>
		<category><![CDATA[speaking]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[I&#8217;m back from Notacon 6 that took place in Cleveland over the weekend and finally have some time to get a post up. All I have to say is&#8230;wow. What a great con! This was my first Notacon (yeah, I live in Cleveland&#8230;sad I know) and I was totally impressed! There was a great line [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://spylogic.net/media/4/20090421-3456342523_078ffe6dd8.jpg" alt="Melt your mind at Notacon!" /><br />
<br />
I&#8217;m back from Notacon 6 that took place in Cleveland over the weekend and finally have some time to get a post up.  All I have to say is&#8230;wow.  What a great con!  This was my first Notacon (yeah, I live in Cleveland&#8230;sad I know) and I was totally impressed!  There was a great line up of speakers, really fun events and a kick ass game room.  The game room was really cool.  They had everything from a fully loaded NES and Commodore 64 for your retro gaming fix as well as Rock Band and Guitar Hero.  Speaking of <a href="http://www.flickr.com/photos/todkat/3453504768/in/pool-notacon">Rock Band</a>&#8230;myself, Chris, Jack, and Jane entered into the Rock Band competition as the &#8220;Notabots&#8221;.  We won the highest score competition and walked away with over a case and a half of <a href="http://www.bawls.com/">Bawls</a> energy drink, a few books and a sweet retro floppy disk clock.  If you know me at all&#8230;the energy drink was the best prize ever! <img src='http://www.spylogic.net/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>Just like most other smaller con&#8217;s the best part is still the great networking opportunities.  One talk that was really outstanding was the talk by James &#8220;<a href="http://twitter.com/Myrcurial">Myrcurial</a>&#8221; Arlen titled <a href="http://www.notacon.org/speakers.html#Arlen">&#8220;From a Black Hat to a Black Suit &#8211; The Econopocalypse Now Edition&#8221;</a>.  His talk is honestly one that anyone wanting to advance their career in Information Security should see.  One thing I took away from his talk was that those of us in Information Security should never forget to mentor others, especially those in an entry level position.  Remember, we were all the new guy just getting our feet wet at some point&#8230;having a mentor is invaluable to the learning process especially in the beginning of your career.  In addition, James is a great guy and is someone who has pretty much &#8220;seen it all&#8221; when it comes to the corporate world.</p>
<p><b>Rise of the Autobots: Into the Underground of Social Network Bots Presentation Materials</b><br />
<a href="http://www.flickr.com/photos/27274410@N07/3458397974/">My presentation went great</a>!  Thanks to everyone that came out to see it and for all the feedback.  I was stoked that we were able to release some really cool code thanks to Robin Wood and announce a <a href="http://socialnetworkbots.com">new open source project</a>.  You can download the <a href="http://www.digininja.org/twitterbot/">Twitterbot POC code here from Robin&#8217;s website</a>.  <a href="http://www.slideshare.net/agent0x0/rise-of-the-autobots-into-the-underground-of-social-network-bots">I posted the slides from my presentation on Slideshare</a> and the video should be up with the rest of the Notacon presentations soon.  This won&#8217;t be the end of this research.  I am hoping to put together a white paper on this subject using the research I have done thus far.  The Notabot code I mentioned is available on the <a href="http://socialnetworkbots.com">socialnetworkbots.com</a> project site which I will talk about more below.</p>
<p><b>UPDATE:</b> The video from my Notacon talk is <a href="http://vimeo.com/4304524">available now to view on Vimeo</a>.</p>
<p><b>Details on the Social Network Bots Open Source Project</b><br />
I created a SourceForge project for all the development for the bot army I am looking to create (joke).  Basically I&#8217;m looking for others interested in developing bots for social networks to join up on the team and contribute code to the project.  I have already talked to some of you at Notacon and there looks like a few of you would like to work on <a href="http://twitter.com/n0tab0t">N0tab0t</a> version 1.1 which might be&#8230;well interesting to say the least!  You can check out the project on socialnetworkbots.com.  We are looking for any kind of social network bot&#8230;not just Twitter bots.  If you want to join in, post something on the project forum or send me an email.</p>
<p>Stay tuned.  Lots of more social media security research goodness coming soon!  Thanks for sticking around for the ride! <img src='http://www.spylogic.net/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2009/04/social-network-bots-presentation-and-my-recap-from-notacon-6/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Speaking at Notacon 6 this week!</title>
		<link>http://www.spylogic.net/2009/04/speaking-at-notacon-6-this-week/</link>
		<comments>http://www.spylogic.net/2009/04/speaking-at-notacon-6-this-week/#comments</comments>
		<pubDate>Wed, 15 Apr 2009 02:50:41 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[bots]]></category>
		<category><![CDATA[notacon]]></category>
		<category><![CDATA[socnetsec]]></category>
		<category><![CDATA[speaking]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[It&#8217;s time to gear up for Notacon 6 which starts for me on Thursday night at 7pm. I will be at the preview night giving a short overview of my presentation on Saturday &#8220;Rise of the Autobots: Into the Underground of Social Network Bots&#8221;. I have been busy tuning and making some last minute updates [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s time to gear up for Notacon 6 which starts for me on Thursday night at 7pm.  I will be at the preview night giving a short overview of my presentation on Saturday <a href="http://www.notacon.org/speakers.html#Eston">&#8220;Rise of the Autobots: Into the Underground of Social Network Bots&#8221;</a>.  I have been busy tuning and making some last minute updates to the presentation.  Some of these last minute updates include some code that myself and a few others have been working on as well as the announcement of a new open source project.  What would a con be without a release of some code right?  This is exciting stuff that I&#8217;m looking forward to talking about in my presentation.  It all goes down at 5pm in the East Ballroom on Saturday.</p>
<p>Shortly after my talk on Saturday I will have my presentation posted as well as links to the code being released and links to the new project I will be talking about.  Stay tuned to this blog for those details over the weekend.  </p>
<p>At Notacon I will also be participating in Notacon Radio with the other co-hosts of the <a href="http://securityjustice.com">Security Justice</a> podcast.  <a href="http://twitter.com/securityjustice">Follow Security Justice on Twitter</a> for details on when we will be live.  We should be doing some interviews with some of the speakers as well.  If you are at the con, stop by and say Hi!  </p>
<p>Some other events at Notacon&#8230;there is a Security Twits meetup taking place on Thursday organized by <a href="http://twitter.com/geekgrrl">@geekgrrl</a>.  If you plan on going you need to RSVP via DM to her like yesterday&#8230;I&#8217;ll be there as well as a few others from Twitter.</p>
<p>I also posted a list of recommended Notacon speakers and events on the Security Justice web site you can check out <a href="http://securityjustice.com/archives/58">here</a> so I won&#8217;t regurgitate the speakers that I will be going to see.  Anyway, I should be live tweeting as I usually do at conferences so be sure to <a href="http://twitter.com/agent0x0">follow me</a> for Notacon updates.</p>
<p>Lastly&#8230;this has been a crazy 2-3 months for me.  Lots of changes going on with things I have been involved with and projects I have been working on.  With all of this activity it has left little time for the blog but I will be getting back into regular posting once things slow down a little so thanks for sticking around.  I am still amazed that this whole social media/networking security research has really taken off for me.  I must have found a niche!  <img src='http://www.spylogic.net/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  I still have a focus on pentesting (mostly for my job) but it&#8217;s cool to see how other interests evolve and morph into greater things.  Such is life right?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2009/04/speaking-at-notacon-6-this-week/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Social Network Bots at Notacon 6!</title>
		<link>http://www.spylogic.net/2009/03/social-network-bots-at-notacon-6/</link>
		<comments>http://www.spylogic.net/2009/03/social-network-bots-at-notacon-6/#comments</comments>
		<pubDate>Mon, 16 Mar 2009 19:13:56 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[bots]]></category>
		<category><![CDATA[notacon]]></category>
		<category><![CDATA[socnetsec]]></category>
		<category><![CDATA[speaking]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[What have I been doing lately? Why the lack of posts? Well&#8230;I have been preparing for my talk at Notacon 6 called Rise of the Autobots: Into the Underground of Social Network Bots. Who are these bots and what are they here for? From my abstract: How do you know that last friend request or [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://spylogic.net/media/4/20090316-ratchet-transformer-movie.jpg" alt="Autobots roll out!" /><br />
<br />
What have I been doing lately?  Why the lack of posts?  Well&#8230;I have been preparing for my talk at <a href="http://notacon.org/">Notacon 6</a> called <a href="http://www.notacon.org/speakers.html#Eston">Rise of the Autobots: Into the Underground of Social Network Bots</a>.  Who are these bots and what are they here for?  From my abstract:</p>
<p><b>How do you know that last friend request or Twitter follower was an actual live human being?  The truth is&#8230;you don&#8217;t!  Bot&#8217;s and bot manufactures have become rampant in social networks such as MySpace, Facebook and Twitter exploiting the trust relationships that make social media work.  Why are bots taking control of social networks?  It&#8217;s simple.  Social networks are the fastest growing phenomenon of our time.  For example, Facebook alone recently reached 150 million potential targets for spammers, malware authors, and other undesirables in 2008.  Social networks are only getting bigger and bots will be part of this trend. </p>
<p>This presentation will take you on a journey into the thriving bot underground where bots are manufactured for every purpose imaginable.  We will talk about good bots, bad bots, *really* evil bots, how to identify bots, terminating bots and the future possibility of social network botnets to rule them all.</b></p>
<p>This talk is the result of many months of research that I have been doing on this subject.  Here are three things from my research as a teaser for my talk:</p>
<p>1.  You will find it fascinating that bots are a huge part of social networks.  Bots are not only used by the bad guys but legitimate users as well.  </p>
<p>2.  There will be discussion on why spammers are targeting social networks and how most of this bot activity falls under the guise of &#8220;<a href="http://en.wikipedia.org/wiki/Search_engine_optimization">Blackhat SEO</a>&#8220;.  I have been finding that there is a thin line between what constitutes &#8220;Blackhat&#8221; vs. &#8220;Whitehat&#8221; and that line will continue to blur.  You will be amazed (as I was) with the business and money making model(s) that spammers and malware authors use.  There is a ton of money being made from using these techniques and tools!  Want an idea how much?  Check out <a href="http://www.youtube.com/watch?v=SIMF8bp5-qg">Jeremiah Grossman&#8217;s recent presentation on Blackhat SEO</a>&#8230;you might want to quit your day job.</p>
<p>3.  How do you use bots to create accounts?  What are the most popular tools available?  How about just buying hacked/bot created accounts in bulk then use these tools to SPAM friends lists?  Also, as a tie in to the tools that are used we will talk about why CAPTCHA&#8217;s and other controls are not working.  Finally, don&#8217;t forget about the new frontier of botnets and social networks&#8230;this is an untapped area thats only going to get more interesting.</p>
<p>So, if you are coming to Notacon 6 (April 16th-19th) hopefully you can stop by.  I promise, my talk will be entertaining!  Stay tuned to this blog&#8230;after the talk I plan on releasing detailed articles on some of the specific topics from the talk.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2009/03/social-network-bots-at-notacon-6/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Want to learn more about Social Engineering?</title>
		<link>http://www.spylogic.net/2009/02/want-to-learn-more-about-social-engineering/</link>
		<comments>http://www.spylogic.net/2009/02/want-to-learn-more-about-social-engineering/#comments</comments>
		<pubDate>Thu, 26 Feb 2009 01:48:12 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[socialengineering]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Of course you do! If you don&#8217;t know who Chris Nickerson is&#8230;then you should. Chris is the founder of Lares Consulting, was on the Tiger Team TV show and also a frequent speaker at security conferences who talks about tiger team/red team operations. He also talks about how social engineering is more important then ever [...]]]></description>
			<content:encoded><![CDATA[<p>Of course you do!  </p>
<p>If you don&#8217;t know who Chris Nickerson is&#8230;then you should.  Chris is the founder of <a href="http://www.laresconsulting.com/">Lares Consulting</a>, was on the Tiger Team TV show and also a frequent speaker at security conferences who talks about tiger team/red team operations.  He also talks about how social engineering is more important then ever to include in your penetration testing program.  I couldn&#8217;t agree more!  In fact, he&#8217;s giving a free webcast with Mike Murray on March 10th called &#8220;Modern Social Engineering &#8211; A Vital Component of Pen Testing&#8221;.</p>
<p><a href="http://carnal0wnage.blogspot.com/2009/02/modern-social-engineering-webcast.html">Via the Carnal0wnage Blog:</a><br />
<b><br />
&#8220;The world of Information Security is changing. Budgets are tighter, attacks are more sophisticated, and the corporate network is no longer the low hanging fruit. That leaves web-enabled applications as the vector-du-jour, but that well is quickly drying up for organized crime as well. As they creep up the OSI Model looking for easier ways to steal your corporate assets, they are quickly making their way up the stack to the unspoken 8th layer, the end user. So what is the next step in the never-ending escalation of this cyber war?</p>
<p>To find out, we must do as Sun Tzu taught. &#8220;Think like our enemy!&#8221; That is, after all, the primary tenet of penetration testing AKA ethical hacking, isn&#8217;t it? After years of hardening physical systems, networks, OSs, and applications, we have now come full circle to a new dawn of attack. People are now the target of the advanced hacker, and the cross-hairs are focused squarely on their foreheads&#8230; literally. It is only a matter of time before corporations feel the pain of wetware hacking requiring a new approach to testing and defense. &#8220;</b></p>
<p>You can <a href="http://www.ethicalhacker.net/content/view/235/1/">sign-up for the webcast here</a>.  Also, Chris and Mike are doing a &#8220;Social Engineering Master Class&#8221; at ChicagoCon this year which looks awesome!  Looks like there are <a href="http://www.chicagocon.com/2009s/semasterclass.html">only 25 seats</a> so check it out if you can.  Interestingly enough <a href="http://secinmotion.blogspot.com/">Chris has just started blogging</a> so be sure to check out his blog.  If that wasn&#8217;t enough&#8230;we (Security Justice) recorded a <a href="http://securityjustice.com/archives/25">special edition podcast</a> with Chris in which he talks about his adventures on the Tiger Team TV show.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2009/02/want-to-learn-more-about-social-engineering/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Using 25 random things against you</title>
		<link>http://www.spylogic.net/2009/02/using-25-random-things-against-you/</link>
		<comments>http://www.spylogic.net/2009/02/using-25-random-things-against-you/#comments</comments>
		<pubDate>Thu, 12 Feb 2009 04:08:38 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[socnetsec]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[I have been seeing a bunch of friends on social networks filling out these &#8220;25 Random Things About Me&#8221; surveys. I just saw another one going around called &#8220;44 Odd Things About You&#8221; as well. I remember this similar type of activity passed along in email several years ago but now it&#8217;s made its way [...]]]></description>
			<content:encoded><![CDATA[<p>I have been seeing a bunch of friends on social networks filling out these &#8220;25 Random Things About Me&#8221; surveys.  I just saw another one going around called &#8220;44 Odd Things About You&#8221; as well.  I remember this similar type of activity passed along in email several years ago but now it&#8217;s made its way to social networks such as Facebook and MySpace.  Here is what the request looks like once you have been &#8220;tagged&#8221; by one of your friends:</p>
<p><b>RULES: Once you&#8217;ve been tagged, you are supposed to write a note with 25 random things, facts, habits, or goals about you. At the end, choose 25 people to be tagged. You have to tag the person who tagged you. If I tagged you, it&#8217;s because I want to know more about you.</b></p>
<p>This sounds fun and a good way to network with your friends, however, let me tell you why putting in this information might be a bad idea.</p>
<p><b>What&#8217;s the big deal?  This is fun&#8230;right?</b><br />
One of the basic rules everyone should be following when using social networks is that you should consider everything you post as public information.  For example, would you write down these 25 random things about you, stick your name on it, make copies and put them in the mailboxes of complete strangers in your neighborhood?  Are all of the people you are friends with truly your friends?  Will they always be your friends?  How is your profile configured?  <a href="http://spylogic.net/downloads/NotesSettings.jpg">Have you looked at your &#8220;Notes&#8221; application settings in Facebook?</a>  More importantly, do you allow your profile to be searched by search engines?  If you posted these 25 random things to your profile and/or wall, you may have inadvertently allowed these things to be found by total strangers.  Remember, personal information on social networks always seems to get out even if you do use the correct privacy settings&#8230;sometimes through no fault of your own.</p>
<p><b>Can I haz your password plz?</b><br />
With these 25 random things about you someone may even be able to use your answers to gain access to your email, other social networks, bank accounts, etc&#8230;why?  <a href="http://spylogic.net/downloads/challenge_questions.pdf">Check out this list of questions that are asked when requesting a &#8220;lost password&#8221; or &#8220;password reset&#8221;</a>.  Many of these are from online banking and other sensitive web sites and looks similar to&#8230;25 random things about you.</p>
<p>Think this doesn&#8217;t happen?  This type of attack <a href="http://blog.wired.com/27bstroke6/2008/09/palin-e-mail-ha.html">did happen to Vice Presidential candidate Sarah Palin last year</a>.  A hacker was able to reset her Yahoo email account password using information he found on her publicly accessible Wikipedia page.  Here is a quote from the Sarah Palin hacker:</p>
<p><b>&#8220;&#8230;after the password recovery was re enabled, it took seriously 45 mins on wikipedia and google to find the info, Birthday? 15 seconds on wikipedia, zip code? well she had always been from wasilla, and it only has 2 zip codes (thanks online postal service!)</p>
<p>the second was somewhat harder, the question was where did you meet your spouse? did some research, and apparently she had eloped with mister palin after college, if you look on some of the screenshots that I took&#8230;so graciously put on photobucket you will see the google search for palin eloped or some such in one of the tabs.</p>
<p>I found out later though more research that they met at high school, so I did variations of that, high, high school, eventually hit on Wasilla high I promptly changed the password to popcorn and took a cold shower&#8221;</b></p>
<p>This could happen to anyone!  So by knowing some of your 25 random things, someone may be able to reset your passwords, impersonate you or even cyberstalk you.  My advise?  Don&#8217;t fill these things out or leave these surveys very general and not too detailed.  Email might even be a safer place for this type of information&#8230;<gasp>.  Stop and think before you post overly detailed information about your life on social networks..it can all potentially be used against you.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2009/02/using-25-random-things-against-you/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>What to attend at ShmooCon 2009</title>
		<link>http://www.spylogic.net/2009/02/what-to-attend-at-shmoocon-2009/</link>
		<comments>http://www.spylogic.net/2009/02/what-to-attend-at-shmoocon-2009/#comments</comments>
		<pubDate>Fri, 06 Feb 2009 01:01:49 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[shmoocon]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[I&#8217;m here in DC getting ready for ShmooCon which starts tomorrow. I had some time to blog before things get crazy later tonight when everyone starts to arrive for the con. UPDATE: Ummm&#8230;someone *may* have hacked the Windows kiosks at the hotel&#8230;saw Ubuntu loading on one and Howard the Duck playing on another&#8230;probably shouldn&#8217;t use [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m here in DC getting ready for ShmooCon which starts tomorrow.  I had some time to blog before things get crazy later tonight when everyone starts to arrive for the con.</p>
<p>UPDATE: Ummm&#8230;someone *may* have hacked the Windows kiosks at the hotel&#8230;saw Ubuntu loading on one and Howard the Duck playing on another&#8230;probably shouldn&#8217;t use those kiosks, huh?</p>
<p>Anyway, I thought I would share some first impressions of the talks and what I will probably attend.  Keep in mind, there are lots of great talks going on all weekend and it will be really hard to make all the ones I want to see but here is my short list of not to miss talks:</p>
<p><strong>Friday, February 6th</strong><br />
<a href="http://shmoocon.org/presentations-all.html#openvulture"><br />
<strong>Open Vulture &#8211; Scavenging the Friendly Skies Open Source UAV Platform</strong></a><br />
Ethan O&#8217;Toole and Matt Davis</p>
<p>An open source UAV? How friggin&#8217; sweet is that?  Now you too can spy on your own neighborhood&#8230; <img src='http://www.spylogic.net/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p><a href="http://shmoocon.org/presentations-all.html#shmooball"><strong>Building the 2008 and 2009 ShmooBall Launchers</strong></a><br />
Larry Pesce and David Lauer</p>
<p>Of course I will be in this one!  Dave from <a href="http://securityjustice.com">Security Justice</a> and Larry from <a href="http://pauldotcom.com">PaulDotCom</a> will be talking all about the new ShmooBall launchers for this year.  Dave and Larry never disappoint and I assume there will be some surprises as well.</p>
<p><a href="http://shmoocon.org/presentations-all.html#smartkey"><strong>Decoding the SmartKey</strong></a><br />
Shane Lawson</p>
<p>I love physical security just about as much as information security so this one should be interesting.  Shane will talk about how to decode the Kwikset SmartKey with materials costing under $5.</p>
<p><a href="http://www.podcastersmeetup.com/"><strong>Podcasters Meetup/HacDC party</strong></a></p>
<p>I will be there along with Matt and Dave from Security Justice.  Looks like we are going to do a live show at 8pm, give away some prizes, start FireTalks then party with the folks from <a href="http://wiki.hacdc.org/index.php?title=Shmoocon_Party">HacDC</a>.  Check out the podcasters meetup site for more details on <a href="http://www.podcastersmeetup.com/">times and official schedule</a>.</p>
<p><strong>Saturday, February 7th</strong><br />
<a href="http://shmoocon.org/presentations-all.html#radiorecon"><br />
<strong>Radio Reconnaissance in Penetration Testing &#8211; All Your RF Are Belong to Us</strong></a><br />
Matt Neely</p>
<p>My friend and fellow co-host of the Security Justice podcast, Matt Neely is doing a talk on ways to use radio reconnaissance in pentests.  Matt does a ton of research with wireless so it should be really interesting to see what new techniques he has come up with.  I hear that Shmoo Balls may be launched during this talk&#8230;. <img src='http://www.spylogic.net/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p><a href="http://shmoocon.org/presentations-all.html#fail2"><strong>Fail 2.0: Further Musings on Attacking Social Networks</strong></a><br />
Nathan Hamiel and Shawn Moyer</p>
<p>I was at BlackHat last year and saw Nathan and Shawn&#8217;s talk titled &#8220;Satan is on my friends list&#8221;.  These guys do great research on social network security and I am looking forward to see the new stuff they came up with for this year.  As a bonus, they should have AFF (Adult Friend Finder) pr0n and related adventures.  <img src='http://www.spylogic.net/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p><a href="http://shmoocon.org/presentations-all.html#mitm"><strong>Man in the Middling Everything with The Middler</strong></a><br />
Jay Beale</p>
<p>Jay Beale is speaking once again about the Middler!  You may remember the Middler was to be released at Defcon last year&#8230;that didn&#8217;t happen for a bunch of reasons.  However, I think Jay will finally be ready to release it!  Jay is a great presenter to boot..highly recommended you attend this one.  Another talk to beware of Shmoo Ball cannon fire&#8230;<br />
<a href="http://shmoocon.org/presentations.html#obgyn"><br />
<strong>802.11 ObgYn or &#8220;Spread Your Spectrum</strong>&#8220;</a><br />
Rick Farina<br />
<a href="http://shmoocon.org/presentations-all.html#packets"><br />
<strong>All Your Packets are Belong To Us: Attacking Backbone Technologies</strong></a><br />
Enno Rey and Daniel Mende</p>
<p><a href="http://shmoocon.org/presentations-all.html#fasttrack"><strong>The Fast-Track Suite: Advanced Penetration Techniques Made Easy</strong></a><br />
David Kennedy</p>
<p>You may remember Dave from <a href="http://securityjustice.com/archives/8">one of the first Security Justice Special Editions last year</a>.  Dave will be going in depth with the Fast-Track suite which is part of Backtrack 3.  Knowing Dave, I&#8217;m sure he will be talking about and/or demoing new features in Backtrack 4.  Shmoo Ball cannon may make an appearance&#8230;</p>
<p><strong>Sunday, February 8th</strong></p>
<p><a href="http://shmoocon.org/presentations-all.html#insanity"><strong>Enough with the Insanity: Dictionary Based Rainbow Tables</strong></a><br />
Matt Weir</p>
<p>Yes! Improvements to rainbow tables&#8230;can&#8217;t wait!</p>
<p><a href="http://shmoocon.org/presentations-all.html#3ric"><strong>RFID Unplugged</strong></a><br />
3ric Johanson</p>
<p>Looks like RFID is going to torn apart in this one&#8230;good stuff!  Interested in the PayPass vulnerabilities he is going to talk about.</p>
<p><a href="http://shmoocon.org/presentations-all.html#0wn"><strong>0wn the Con</strong></a><br />
The Shmoo Group</p>
<p>What to know what it takes to put ShmooCon together?  Be sure to check out this talk and learn how it&#8217;s all done.</p>
<p>If you are around the con send me a tweet on <a href="http://twitter.com/agent0x0">Twitter</a> or stop by the <a href="http://www.podcastersmeetup.com/">Podcasters Meetup</a> if you want to chat!  Hoping I can blog and/or live Tweet from some of the talks.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2009/02/what-to-attend-at-shmoocon-2009/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Twitter for Information Gathering</title>
		<link>http://www.spylogic.net/2009/01/twitter-for-information-gathering/</link>
		<comments>http://www.spylogic.net/2009/01/twitter-for-information-gathering/#comments</comments>
		<pubDate>Sun, 25 Jan 2009 12:00:00 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[informationgathering]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[If you are interested in using Twitter for information gathering/mining about potential targets for a penetration test or for &#8220;other&#8221; research&#8230;I highly recommend the very comprehensive article that Lenny Zeltser from SANS put together. Twitter is really becoming a great tool for not just marketing yourself or your business but also to find out detailed [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://spylogic.net/media/4/20090123-twitter.jpg" alt="Twitter!" /><br />
<br />
If you are interested in using Twitter for information gathering/mining about potential targets for a penetration test or for &#8220;other&#8221; research&#8230;<a href="http://isc.sans.org/diary.html?storyid=5728">I highly recommend the very comprehensive article that Lenny Zeltser from SANS put together</a>.  Twitter is really becoming a great tool for not just marketing yourself or your business but also to find out detailed information about a company, individual or organization.</p>
<p>One thing I would add to Lenny&#8217;s article is that social media in general is the new &#8220;hotness&#8221; when it comes to information gathering and reconnaissance.  If you are a penetration tester you <i>really</i> need to start leveraging all the information contained in social networks!  Better yet, use <a href="http://www.paterva.com/maltego/">Maltego</a> which can help search multiple social networks and visually show you this data.  You can even hit up the Twitter API with <a href="http://ctas.paterva.com/view/Specification">local transforms</a> in the new version of Maltego&#8230;yummy!</p>
<p>Twitter photo via <a href="http://thestylepaathome.blogspot.com">Jenny Hayden</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2009/01/twitter-for-information-gathering/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Who&#8217;s managing information security in your city?</title>
		<link>http://www.spylogic.net/2009/01/whos-managing-information-security-in-your-city/</link>
		<comments>http://www.spylogic.net/2009/01/whos-managing-information-security-in-your-city/#comments</comments>
		<pubDate>Fri, 23 Jan 2009 04:07:04 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[networksecurity]]></category>
		<category><![CDATA[patching]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[There was something shocking in my local suburban newspaper today. I opened up to page two and behold&#8230;an article that touched on information security! Specifically, the article was about how a small municipal court system in my area had a PC that was infected by an email &#8220;virus&#8221;. This virus caused a &#8220;hard drive to [...]]]></description>
			<content:encoded><![CDATA[<p>There was something shocking in my local suburban newspaper today.  I opened up to page two and behold&#8230;an article that touched on information security!  Specifically, the article was about how a small municipal court system in my area had a PC that was infected by an email &#8220;virus&#8221;.  This virus caused a &#8220;hard drive to shut down&#8221;.  Shut down I would assume means the MBR was corrupted or the PC was so bogged down with malware that it had to be rebuilt.  Don&#8217;t worry, it gets better.  The reporter goes on to say that an employee opened an email that had something to do with Nigeria and winning money.  Hmmm&#8230;<a href="http://www.eweek.com/c/a/Security/Keeping-an-Eye-Out-for-the-Sinowal-Trojan/">Sinowal Trojan</a> perhaps?  Regardless, the reporter goes into details from the interview he did with the city &#8220;IT manager&#8221;.  Here are some quotes from the article:</p>
<p><b>&#8220;The court computer system has a small firewall, he said, but the anti-virus on the computer was either non-existent or never upgraded.&#8221;</b></p>
<p><b>&#8220;The IT manager has been trying to bring the city computer systems up to speed.  There hasn&#8217;t been a system-wide upgrade in years.&#8221;</b></p>
<p><b>&#8220;The employee opened the email because there&#8217;s no formal training.&#8221;</b></p>
<p><b>&#8220;One of his goals is to work out a way he can send out software updates, especially anti-virus, to all city computers at night when they aren&#8217;t in use.&#8221;</b></p>
<p>I like this one the best&#8230;</p>
<p><b>&#8220;The main issue is spending the money for software, licenses and equipment.  It&#8217;s pretty down-to-earth-basic, he said.  &#8220;You&#8217;ve got to start throwing money around to get it to work.&#8221;</b></p>
<p>Huh?  Throw money at the problem&#8230;classic. Multiple levels of FAIL right?  Oh, if you haven&#8217;t figured it out yet&#8230;read those quotes again.  What would a hacker think about after reading this newspaper article?  This court/city computer system is a target rich environment to say the least!</p>
<p>While we could talk all day about how the city could implement a better more cost effective solution to the issues, there are two main problems that I see:</p>
<p><b>Be careful what you say to the media after an incident</b><br />
The IT manager gave out way too much information to the media about the problems the city is facing with IT security issues.  Just by reading this article someone with bad intentions and a bit of technical skill now knows that the city employs non security aware people and the entire network probably hasn&#8217;t been patched in years.  This would be even more scary if police and fire computer systems were on the same network!  However, the article did point out that police and fire systems are on a separate network.  Yet, things don&#8217;t look good for the police and fire networks if this same IT manager is running those as well! :-/  Local city government should carefully review all media requests for information about an incident.</p>
<p><b>Local cities, municipal court systems, fire and police networks are left for dead</b><br />
This doesn&#8217;t surprise me but just like a lot of small businesses, small city governments or suburbs don&#8217;t spend the money or have the staff to keep systems patched or up-to-date.  Especially in a recession!  Your IT guy or contracted support is an easy thing to cut for a city.  I would think that most city networks are in worse shape then some home PC networks because of outdated equipment, knowledge and lack of funds.  Case in point, <a href="http://spylogic.net/item/266">I wrote about a potentially dangerous vulnerability that was found on another local city network last year</a>.  Luckily this city took the vulnerability seriously, resolved the issue and hopefully improved their security.</p>
<p>Imagine the problems that could happen if police, fire and court systems were breached or compromised.  Critical infrastructure like police and fire networks are at serious risk with unsecured systems that are not maintained.  As a citizen that lives and works in these cities you should question your local city government about how they maintain and manage their networks.  I have an email en route to the mayor of this city that will hopefully help them with some ideas and suggestions to get them back on track.  However, I think we may only be scratching the surface of the problem.  Lets hope your city takes computer and network security more seriously.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2009/01/whos-managing-information-security-in-your-city/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Social Media Security on the Streetwise Security Zone Podcast</title>
		<link>http://www.spylogic.net/2009/01/social-media-security-on-the-streetwise-security-zone-podcast/</link>
		<comments>http://www.spylogic.net/2009/01/social-media-security-on-the-streetwise-security-zone-podcast/#comments</comments>
		<pubDate>Mon, 12 Jan 2009 21:00:00 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[podcast]]></category>
		<category><![CDATA[socialmedia]]></category>
		<category><![CDATA[socnetsec]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Late last week I was a guest on the Streetwise Security Zone Podcast talking about my Facebook Privacy &#038; Security guide, social media security as well as some other interesting security topics. I highly recommend you check out some of the great things that Scott Wright has put together. He has built a security community [...]]]></description>
			<content:encoded><![CDATA[<p>Late last week <a href="http://www.streetwise-security-zone.com/members/streetwise/blog/VIEW/00000012/00000069/SWSZ-Episode-3---January-10-2009---Facebook-and-security-for-social-media-with-Tom-Eston.html">I was a guest on the Streetwise Security Zone Podcast</a> talking about my <a href="http://spylogic.net/item/370">Facebook Privacy &#038; Security guide</a>, social media security as well as some other interesting security topics.  </p>
<p>I highly recommend you check out some of the great things that Scott Wright has put together.  He has built a security community focused on security awareness for businesses and you may also know Scott as the creator of the <a href="http://www.honeystickproject.com/">Honey Stick Project</a>.  Good stuff to check out!  I look forward to working with Scott more in the future.  </p>
<p>You can check out <a href="http://www.streetwise-security-zone.com">the Streetwise Security Zone web site</a> and <a href="http://itunes.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=298647305">podcast</a> for more information.  Definitely another security podcast to add to your play list!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2009/01/social-media-security-on-the-streetwise-security-zone-podcast/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Maltego 2.0.2 Released with Local Transforms!</title>
		<link>http://www.spylogic.net/2009/01/maltego-202-released-with-local-transforms/</link>
		<comments>http://www.spylogic.net/2009/01/maltego-202-released-with-local-transforms/#comments</comments>
		<pubDate>Fri, 09 Jan 2009 16:19:58 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[informationgathering]]></category>
		<category><![CDATA[maltego]]></category>
		<category><![CDATA[pentest]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Just a quick blog post about the latest release of Maltego that was just announced. This is great! You can now create custom transforms that will integrate directly with Maltego! This is something that many of us have requested and it&#8217;s finally here. From first glance it looks like you can code them in any [...]]]></description>
			<content:encoded><![CDATA[<p>Just a quick blog post about the <a href="http://www.paterva.com/maltego/maltego-202-released-local-transforms/">latest release of Maltego that was just announced</a>.  This is great!  You can now create custom transforms that will integrate directly with Maltego!  This is something that many of us have requested and it&#8217;s finally here.  From first glance it looks like you can code them in any language as well.  Should be interesting to see what the community comes up with in regards to transforms now.  I know I have some ideas&#8230;.</p>
<p>Oh and if that wasn&#8217;t enough the pentest entities are now also available locally!</p>
<p>Great work Maltego team!  <a href="http://www.paterva.com/maltego/maltego-202-released-local-transforms/">Check out the full announcement here</a>.</p>
<p><b>What is Maltego if you don&#8217;t know about it?</b><br />
&#8220;Maltego is a unique platform developed to deliver a clear threat picture to the environment that an organization owns and operates. Maltego&#8217;s unique advantage is to demonstrate the complexity and severity of single points of failure as well as trust relationships that exist currently within the scope of your infrastructure.</p>
<p>The unique perspective that Maltego offers to both network and resource based entities is the aggregation of information posted all over the internet &#8211; whether it&#8217;s the current configuration of a router poised on the edge of your network or the current whereabouts of your Vice President on his international visits, Maltego can locate, aggregate and visualize this information.&#8221;</p>
<p>Read more about Maltego <a href="http://ctas.paterva.com/view/What_is_Maltego">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2009/01/maltego-202-released-with-local-transforms/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Summary of the Twitter Security Incidents</title>
		<link>http://www.spylogic.net/2009/01/summary-of-the-twitter-security-incidents/</link>
		<comments>http://www.spylogic.net/2009/01/summary-of-the-twitter-security-incidents/#comments</comments>
		<pubDate>Thu, 08 Jan 2009 05:56:05 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[socnetsec]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[I won&#8217;t beat a dead horse&#8230;we all know that Twitter had a few *security issues* this week. The good news is that usually once something like this happens to a company (especially one that gets so much media attention) things start to change and security gets taken a bit more seriously. Lets remember that Twitter [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://spylogic.net/media/4/20090108-ricksanchezcnn_hacked.jpg" alt="One of the 33 pwnd Twitter accounts" /><br />
<br />
I won&#8217;t beat a dead horse&#8230;we all know that Twitter had a few *security issues* this week.  The good news is that usually once something like this happens to a company (especially one that gets so much media attention) things start to change and security gets taken a bit more seriously.  Lets remember that Twitter suffers from the traditional security problem of not building an application with security in mind, however, lets hope these issues bring change to one of the most used social media services.</p>
<p>Below is the break down of events with some of my own comments and links to good articles that detail out everything that happened.</p>
<p><b>#1 Twitter Phishing Attack</b><br />
I wrote a <a href="http://spylogic.net/item/396">blog post</a> about this a few days ago.  Basically, this is no different then what you see in any other traditional phishing attack except that this is the first time Twitter was targeted on a large scale.  Some have even said this was a &#8220;worm&#8221; because of the way that the phish propagated.  </p>
<p>Once a user clicked on the bogus link, entered in their Twitter credentials&#8230;their Twitter account was compromised and automatically used to send DM&#8217;s (direct messages) to others the compromised user was following.  Twitter quickly reacted and worked with blogspot and others to shut down the redirect.  However, the web site that hosts the fake Twitter sign-on page is still active and is even being used to phish Facebook users!  Why is this not shutdown? Long story but the site is hosted in China and that presents a whole host of issues to get the site taken down.  The good news is that if you try to go to the URL in Firefox or Safari the phishing filter kicks in and stops you from going there.  I haven&#8217;t tested IE 7&#8230;and neither should you. <img src='http://www.spylogic.net/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  </p>
<p>On a side note, I agree that <a href="http://en.wikipedia.org/wiki/OAuth">OAuth</a> (or something like FriendFeed&#8217;s Remote Key) should be implemented as part of an overall security strategy for Twitter but would not prevent traditional phishing attempts like this from happening (<a href="http://blog.wired.com/business/2009/01/phishing-scams.html">some others share this opinion as well</a>).  OAuth is good for authenticating third-party applications (like Twillow or Twitterfeed) that require your Twitter credentials to access your account and do things on your behalf.  <a href="http://www.louisgray.com/live/2009/01/hey-twitter-its-not-just-worm-its-app.html">Lot&#8217;s of discussion going on the blogs about this</a> and I&#8217;m sure it will continue.</p>
<p><b>Links that have good information about the Twitter phish:</b> <a href="http://blog.twitter.com/2009/01/gone-phishing.html">Twitter&#8217;s Blog</a>, <a href="http://blogs.zdnet.com/feeds/?p=382">Naivete: Web 2.0&#8242;s biggest security threat</a> and an article over at <a href="http://www.twittertruth.com/?p=38">Twitter Truth</a></p>
<p><b>#2 Twitter gets Hacked</b><br />
This was not related to the phishing incident.  Pure weird coincidence that this happened right after users started to figure out what happened with the phishing issue.  Ironically, many of us on Twitter (including myself) thought that this was related to phishing after we saw @foxnews get owned but once <a href="http://www.flickr.com/photos/27895091@N08/3171351420/">Britney Spears</a>, Obama and others started showing up with strange tweets many of us knew there was something else going on.</p>
<p>Basically, an 18 year old who wanted to &#8220;pen-test Twitter&#8221; decided to build a Twitter brute force application that would try common dictionary words against at specific Twitter account.  One problem with the current Twitter security model is that there is no lockout policy, meaning, you can try as many failed passwords as you like until you get lucky with the correct password.  This guy found one of the accounts used by the Twitter support people (Crystal) and brute forced the password using his tool.  Password of &#8220;happiness&#8221; was found and he was in!  There was a password reset feature in the administrative panel that allowed him to reset the password and change the email address of any Twitter account.  He didn&#8217;t use the accounts himself, rather&#8230;he posted that he had access to 33 accounts and gave access to others in a hacker forum that requested the accounts.  You can read more about this in the Wired article below as well as see the YouTube video that the hacker put up to prove he did the hack.</p>
<p><a href="http://blog.wired.com/27bstroke6/2009/01/professed-twitt.html">Weak Password Brings &#8216;Happiness&#8217; to Twitter Hacker</a></p>
<p><b>How does Twitter get fixed?</b><br />
Security is always about compromise and with Twitter in particular there has to be a balance between usability and secure features.  <a href="http://securabit.com/2009/01/07/securabyte-episode-05-happiness-fail-whale-beaches-itself/">I was a guest on the SecuraByte podcast</a> the other night talking about the recent Twitter security issues as well as how to secure social media in general.  We came to the conclusion that there is no good answer.  However, we all agreed that there has to be a mix between technical and non-technical solutions.  The technical being better forms of authentication and basic web application security controls (account lockout, email verification..as examples) for starters.  On the non-technical side there has to be more basic security education (setting unique hard to guess passwords as an example) focused on the users of social media through lots of different means.  There is no good answer to these problems and there are many different opinions but hopefully we can all come to some common ground so we can all make social media more secure for everyone.</p>
<p>Here are a few good links with things that Twitter should consider when re-evaluating the current model:</p>
<p><a href="http://threatchaos.com/2009/01/ten-security-measures-for-social-networking-sites/">Ten Security Measures for Social Networking sites</a> &#8211; ThreatChaos<br />
<a href="http://factoryjoe.com/blog/2009/01/02/twitter-and-the-password-anti-pattern/">Twitter and the Password Anti-Pattern</a> &#8211; FactoryCity<br />
<a href="http://blogs.zdnet.com/feeds/?p=384">The inevitable rise (and fall?) of &#8220;twishing&#8221;</a> &#8211; Jennifer Leggio ZDnet (guest post by Damon Cortesi)</p>
<p>I think we can all agree that Twitter needs to do something soon as the current security model is not sustainable for very much longer.  </p>
<p>What are your thoughts on the recent Twitter security issues and social media security in general?  How do you think we can we make social media more secure?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2009/01/summary-of-the-twitter-security-incidents/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>First Twitter Phishing Attack of 2009</title>
		<link>http://www.spylogic.net/2009/01/first-twitter-phishing-attack-of-2009/</link>
		<comments>http://www.spylogic.net/2009/01/first-twitter-phishing-attack-of-2009/#comments</comments>
		<pubDate>Sun, 04 Jan 2009 02:02:12 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[socnetsec]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Welcome to 2009! As many have said&#8230;it was just a matter of time before Twitter had a somewhat significant attack&#8230;well, here it is! I just had a post up last week about how many of us that use social media just blatantly trust every site that asks us for Twitter credentials. Well if you don&#8217;t [...]]]></description>
			<content:encoded><![CDATA[<p>Welcome to 2009!  As many have said&#8230;it was just a matter of time before Twitter had a somewhat significant attack&#8230;well, here it is!  I just <a href="http://spylogic.net/item/388">had a post up last week</a> about how many of us that use social media just blatantly trust every site that asks us for Twitter credentials.  Well if you don&#8217;t look at the URL carefully even the security aware could be fooled by this one.  Tonight there was a lot of tweets about the following phishing attack&#8230;.</p>
<p>You will get a DM (direct message) in your email from a user with the following message:</p>
<p><b>hey! check out this funny blog about you&#8230;<br />
hxxp://jannawalitax.blogspot.com</b></p>
<p>If you click on blogspot link this is basically a redirect to the following fake Twitter site:</p>
<p><img src="http://spylogic.net/media/4/20090103-phishing4.jpg" alt="Twitter Phishing Site" /><br />
<br />
Looks just like an identical copy of the real Twitter site except for the URL! (don&#8217;t go to this URL&#8230;)</p>
<p>About an hour after this started going around Twitter it looked like Firefox 3 picked up that this was a reported phishing site and you now get the following message:</p>
<p><img src="http://spylogic.net/media/4/20090103-forgery.jpg" alt="Web Forgery Reported" /><br />
<br />
Looks like Twitter and others moved quickly to get the redirect shut down.  If ignore the Firefox warning to the blogspot page you get this:</p>
<p><img src="http://spylogic.net/media/4/20090103-removed.jpg" alt="Removed" /><br />
<br />
However, <b>the phishing site is still active and will probably be for awhile</b>.  <b>Do not enter in any login credentials at any site other then twitter.com.  The fake site in this case is twitter.access-logins.com/login.</b>  Note that if you take off the &#8220;login&#8221; at the end of the URL you are sent to a fake Facebook login page!  Looks like these guys have been doing this for quite some time.</p>
<p>One interesting note about this attack&#8230;how does someone send you a DM without you following them?  There <a href="http://blog.twilightfairy.in/2008/09/19/send-twitter-dm-to-non-followers/">was an interesting hack that is documented here</a> that used to work, however&#8230;Twitter fixed this a few months ago.  My only guess is that multiple hacked accounts were used to send legitimate DM&#8217;s.  I&#8217;m not 100% sure how DM&#8217;s are being propagated in this case but it should be interesting to find out how the attack started in the coming days.</p>
<p>Kudos to the Twitter team and all the Twitter users that retweeted and got to word out.  This alone hopefully mitigated much of the threat.  I even saw in the Twitter web client that @twitter posted a warning message on the page about the threat.  Great work Twitter team!</p>
<p><b>What if you gave your credentials away to this site?</b><br />
Change your password immediately!  Also, do you use this same password for Facebook, Myspace, email and other sites?  Change those as well!  Give a password manager like <a href="http://agilewebsolutions.com/products/1Password">1password</a> or <a href="http://keepass.info/">KeePass</a> (KeePass is free BTW) a try to set unique passwords for every site/application you use.  That way if your Twitter account did get compromised, your other accounts are safe.  <a href="http://spylogic.net/item/340">See this post</a> for more information.  </p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2009/01/first-twitter-phishing-attack-of-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What&#8217;s behind that short URL?</title>
		<link>http://www.spylogic.net/2008/12/whats-behind-that-short-url/</link>
		<comments>http://www.spylogic.net/2008/12/whats-behind-that-short-url/#comments</comments>
		<pubDate>Mon, 29 Dec 2008 15:05:24 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[There was a good post over at ThreatChaos the other day about a new Firefox extension which will automatically show you the real URL&#8217;s of shortened URL&#8217;s. What is URL shortening? For example&#8230;this long URL: http://www.google.com/maps?f=q&#038;hl=en&#038;geocode=&#038;q=washington+dc&#038;sll=37.0625,-95.677068&#038;sspn=33.764224,56.25&#038;ie=UTF8&#038;ll=38.905996,-77.023773&#038;spn=0.25915,0.439453&#038;z=11&#038;g=washington+dc&#038;iwloc=addr becomes&#8230; http://tinyurl.com/9lum95 By using a service like Tinyurl or one of the many other sites available you can easily [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://spylogic.net/media/4/20081229-plzclickme.jpg" alt="plz click this short url" /></p>
<p>There was a <a href="http://threatchaos.com/2008/12/great-idea-long-urls-might-save-twitter/">good post over at ThreatChaos</a> the other day about <a href="http://www.longurlplease.com/">a new Firefox extension</a> which will automatically show you the real URL&#8217;s of shortened URL&#8217;s.  What is URL shortening?  For example&#8230;this long URL:</p>
<p>http://www.google.com/maps?f=q&#038;hl=en&#038;geocode=&#038;q=washington+dc&#038;sll=37.0625,-95.677068&#038;sspn=33.764224,56.25&#038;ie=UTF8&#038;ll=38.905996,-77.023773&#038;spn=0.25915,0.439453&#038;z=11&#038;g=washington+dc&#038;iwloc=addr</p>
<p>becomes&#8230;</p>
<p>http://tinyurl.com/9lum95</p>
<p>By using a service like Tinyurl or one of the <a href="http://www.dmoz.org/Computers/Internet/Web_Design_and_Development/Hosted_Components_and_Services/Redirects/">many other sites available</a> you can easily shorten a URL so your friends don&#8217;t freak when you send them long links.  When it comes to Twitter it becomes almost mandatory that you shorten that long URL to meet the 140 character limit in your tweets.</p>
<p><strong>What&#8217;s the problem?</strong><br />
Getting people to click on a malicious link just got easier with these services.  Sure, people will still click on strange URL&#8217;s without a mask (even manually typing in strange URL&#8217;s as I showed in <a href="http://blog.blogsecurify.com/2008/11/analysis-of-new-facebook-phish.html">this post</a>), however, by masking *any* URL with these services a phishing or malware attack can be even more successful.</p>
<p>Also, how can you *easily* see what the real site is behind one of these short URL&#8217;s?  TinyURL and others offer you a service to &#8220;preview&#8221; URL&#8217;s but many sites don&#8217;t offer this and who is actually going to attempt to manually verify what is behind those links?  That&#8217;s way too much work.</p>
<p>Another problem is that some of these short URL services allow you to obfuscate an already short URL with another short URL.  Take for example Xrl.in.  The TinyURL above (http://tinyurl.com/9lum95) becomes http://xrl.in/1b0i.  This throws off the preview feature of many sites like this.  This problem could add multiple redirects and levels of obfuscation to malicious links.  All it takes is the right combination of short URL sites.</p>
<p>Right before I was about to post this I saw <a href="http://blogs.zdnet.com/feeds/?p=370">a post by Jennifer Leggio over at ZDNet regarding the URL redirection issue</a>.  She mentions that FriendFeed has implemented a feature that reveals short URL&#8217;s if you hover your mouse over the links.  This is great&#8230;for FriendFeed, what about other more popular social media sites?  <a href="http://blogs.zdnet.com/feeds/?p=370">Check out her article</a> for a good overview of the issue and some interesting information about what other social media sites are doing and <em>not</em> doing about this problem.</p>
<p><strong>The &#8220;Long URL Please&#8221; Solution</strong><br />
While not 100% perfect <a href="http://www.longurlplease.com/">this a great start</a> and it looks like the developer is working on improving the Firefox extension and API.  You can even use it with other web browsers besides Firefox with a bookmarklet available on his site.  Simply click on the bookmarklet and it will transform all the short URL&#8217;s on the web page currently loaded.</p>
<p>The <a href="http://www.longurlplease.com/">Long URL Please Firefox</a> extension will automatically show you the true URL of 30 supported short URL site&#8217;s.  No hovering over a link or clicking to a site to preview it.  It just shows you the link&#8230;no extra work on your part.  This works great for the Twitter web client as well as any web page that has a link from one of the 30 supported services.  One problem I saw was that short URL sites like xrl.in and others will keep popping up (I listed a site above that links 70 of these services).  It&#8217;s going to take some work from the developer side to keep up with all of these new services.  In addition, this doesn&#8217;t help with Twitter applications like ones that are Adobe Air based or developed using another type of framework.  However, it <a href="http://longurlplease.blogspot.com/2008/12/example-of-using-long-url-please-in.html">looks like the developer is working on it</a> and he is trying to get other applications to integrate to his API.  Either way, check out this great extension and <a href="http://twitter.com/longurlplease">follow the developer on Twitter</a> to get news on improvements.  I look forward to see how this type of extension will evolve.</p>
<p>Short URL&#8217;s won&#8217;t be going anywhere soon&#8230;lets hope social media applications and end users start using them with a little bit security in mind.</p>
<p>What solutions do you think could solve the short URL problem?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2008/12/whats-behind-that-short-url/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>JanusPA &#8211; Hardware Privacy Adapter</title>
		<link>http://www.spylogic.net/2008/12/januspa-hardware-privacy-adapter/</link>
		<comments>http://www.spylogic.net/2008/12/januspa-hardware-privacy-adapter/#comments</comments>
		<pubDate>Tue, 23 Dec 2008 15:45:25 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Privacy on the Internetz]]></category>
		<category><![CDATA[januspa]]></category>
		<category><![CDATA[tor]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[This is really cool. The guys that brought you the JanusVM Internet Privacy Appliance are about to release instructions on how to make a hardware privacy adapter. What is a hardware privacy adapter you ask? Via Hack a day: &#8220;It&#8217;s a small two port router. You just plug it in-line between your computer&#8217;s switch and [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.janusvm.com/goldy/JanusPA/index.html">This is really cool</a>.  The guys that brought you the <a href="http://www.janusvm.com/">JanusVM Internet Privacy Appliance</a> are about to release instructions on how to make a <a href="http://www.janusvm.com/goldy/JanusPA/index.html">hardware privacy adapter</a>.  What is a hardware privacy adapter you ask?</p>
<p>Via <a href="http://hackaday.com/2008/12/21/tor-hardware-privacy-adapter/">Hack a day</a>:</p>
<p><b>&#8220;It&#8217;s a small two port router. You just plug it in-line between your computer&#8217;s switch and your internet connection. It will then anonymize all of your traffic via the Tor network. You can also use it with OpenVPN. The hardware appears to be a Gumstix computer mounted to a daughtercard with two ethernet ports. It will have a web configuration just like a standard router. This looks like a great plug-n-play privacy device.&#8221;</b></p>
<p>Once you buy all the parts you can build your own for about $250.  Not too bad for an easy way to anonymize all of your traffic over the Tor network or a VPN.  <a href="https://www.torproject.org/">Tor</a> and <a href="http://www.privoxy.org/">Privoxy</a> can sometimes be a real pain to configure so something like this would be fantastic to just plug in and configure once.  It&#8217;s also nice that is can use <a href="http://www.openvpn.net/">OpenVPN</a> as well.  </p>
<p>My only issue with <a href="https://www.torproject.org/">Tor</a> is that it can be *really* slow for web surfing depending on what relays you connect to and there are <a href="https://www.torproject.org/download.html.en#Warning">some warnings you should be aware of</a>.  Also, your Tor installation needs to be updated frequently as the development team <a href="http://archives.seul.org/or/announce/Dec-2008/msg00000.html">is always making updates and improvements</a>.  However, Tor is better then nothing if you are concerned with online anonymity.</p>
<p>Kudos to the JanusPA team&#8230;looks like I might have a hardware project to work on next year once the instructions get released.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2008/12/januspa-hardware-privacy-adapter/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Who are you giving your Twitter account to?</title>
		<link>http://www.spylogic.net/2008/12/who-are-you-giving-your-twitter-account-to/</link>
		<comments>http://www.spylogic.net/2008/12/who-are-you-giving-your-twitter-account-to/#comments</comments>
		<pubDate>Tue, 16 Dec 2008 05:00:00 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[socnetsec]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[It&#8217;s always interesting to me when I check out a new Twitter application, it always seems to ask you to &#8220;verify&#8221; your account or ask you to pass your Twitter user name/password to their application. This of course is done without any protections or any way of knowing what happens to your account information on [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://spylogic.net/media/4/20081215-twellow.jpg" alt="Twellow anyone?" /><br />
<br />
It&#8217;s always interesting to me when I check out a new Twitter application, it always seems to ask you to &#8220;verify&#8221; your account or ask you to pass your Twitter user name/password to their application.  This of course is done without any protections or any way of knowing what happens to your account information on the other end.  </p>
<p>Take for example a recent find called <a href="http://www.twellow.com/">Twellow</a> which is basically a big directory of Twitter users (like the yellow pages).  Twellow has some neat features like searching for other Twitter users by keywords and interests.  Twellow like many of these types of Twitter applications work by scraping public timelines to populate their site with your information.  Twellow asks you to &#8220;claim&#8221; your profile by putting in your Twitter password.  This is where it gets interesting&#8230;  </p>
<p>To the unsuspecting user it&#8217;s tempting to just give your credentials away to every website that asks for it.  Twellow is a good looking, legitimate website right?  Did you stop to think what could happen to your login credentials?  Can you really trust that they don&#8217;t record your credentials?  The disclaimer says they don&#8217;t use your password for anything&#8230;you trust <i>everyone</i> right? <img src='http://www.spylogic.net/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p><b>What&#8217;s your Twitterank?</b><br />
If you are a heavy Twitter user you may remember the <a href="http://mashable.com/2008/11/14/twitterank-phishing/">Twitterank fiasco about a month ago</a>.  Like many people on Twitter just hearing of a website that will calculate your &#8220;rank&#8221; on Twitter sounded like a cool idea.  No harm in this right?  <a href="http://www.sciencetext.com/twitterank-phishing-scam.html">Rumors quickly spread</a> on Twitter and in the blogosphere that Twitterank was a phishing site and that the <a href="http://ryo.iloha.net/">developer</a> was harvesting Twitter accounts.  It ended up that this was <a href="http://blogs.zdnet.com/collaboration/?p=164">most likely a legitimate application</a>&#8230;BUT&#8230;why do you trust it?  Why as social media users do we blatantly trust every Twitter or social media developer out there?  No offense to the developer of Twitterank but there are way too many of these sites out there that ask for your account information.  A real Twitter phishing site is easy to do using these same tactics.  All you need is a legitimate looking website that preys on human weakness&#8230;we all want more followers and more rankage, right?  For example, if you want to see a spoof Twitter phishing site, check out <a href="http://www.twitterphishr.com/">Twitter Phisher</a> done by the fine folks over at <a href="http://www.hak5.org/">Hak5</a> (be sure to view source in your browser for some extra lolz).</p>
<p><b>What&#8217;s the fix?</b><br />
First, social media users need more education.  Seriously, don&#8217;t just give your credentials away to anyone that asks for it (this actually applies to everything in life).  Is your Twitter ranking really that important?  </p>
<p>If you did give your credentials away, hopefully you used a different and unique password for that particular account.  That way, if your account did get compromised then only one account is compromised, not your entire portfolio of accounts.  How do you manage multiple passwords?  Give a password manager like <a href="http://agilewebsolutions.com/products/1Password">1password</a> or <a href="http://keepass.info/">KeePass</a> a try to create and manage unique passwords for each of your social media accounts.</p>
<p>Secondly, social media websites like Twitter need to use better forms of authentication. How about something similar to what <a href="http://friendfeed.com/api/faq#remotekey">FriendFeed is doing by issuing users a &#8220;remote key&#8221;</a> for all third-party interactions with your account.  Of course this isn&#8217;t perfect but it&#8217;s a step in the right direction.  I applaud <a href="http://friendfeed.com/">FriendFeed</a> for having the remote key functionality a required part of the API.  BTW, Twitter has been talking about using nifty solutions like <a href="http://oauth.net/">OAuth</a>, so do it already @Twitter!  <a href="http://apiwiki.twitter.com/REST+API+Documentation#Authentication">HTTP Basic Authentication</a> just doesn&#8217;t cut it.</p>
<p>Authentication of user credentials and social media is a big problem&#8230;(actually verifying who you say you are is a another topic altogether).  What authentication solutions for social media do you think should be adopted?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2008/12/who-are-you-giving-your-twitter-account-to/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Notacon 6 Speaker Update</title>
		<link>http://www.spylogic.net/2008/12/notacon-6-speaker-update/</link>
		<comments>http://www.spylogic.net/2008/12/notacon-6-speaker-update/#comments</comments>
		<pubDate>Mon, 15 Dec 2008 14:53:44 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Cleveland]]></category>
		<category><![CDATA[notacon]]></category>
		<category><![CDATA[speaking]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Looks like the Notacon website has updated the speaker list and there looks to be some really good talks so far. Here is the list from the Notacon 6 website and blog post: Time To Replicate The Real Threat: Client Side Penetration Testing CG &#038; g0ne Interactivity with Arduinos, Transducing the Physical World droops &#038; [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://spylogic.net/media/4/20081215-NAClogo.jpg" alt="Notacon Logo" /><br />
<br />
Looks like the Notacon website has updated the speaker list and there looks to be some really good talks so far.  Here is the list from the <a href="http://www.notacon.org/speakers.html">Notacon 6 website</a> and <a href="http://blog.notacon.org/?p=40">blog post</a>:</p>
<p><b>Time To Replicate The Real Threat: Client Side Penetration Testing </b><br />
<a href="http://www.notacon.org/speakers.html#CG">CG &#038; g0ne</a></p>
<p><b>Interactivity with Arduinos, Transducing the Physical World</b><br />
<a href="http://www.notacon.org/speakers.html#droops">droops &#038; Morgellon the Lowtek Mystic</a></p>
<p><b>Fun With The MSP430 MCU </b><br />
<a href="http://www.notacon.org/speakers.html#Goodspeed">Travis Goodspeed</a></p>
<p><b>Hacking Light &#8211; How we came to love Holga and Other Stories of photo hi jinx</b><br />
<a href="http://www.notacon.org/speakers.html#jeontreize">Jeon &#038; Treize</a></p>
<p><b>&#8220;Pilates&#8221; for Common Cubicle Injuries </b><br />
<a href="http://www.notacon.org/speakers.html#Martaus">Michele Martaus</a></p>
<p><b>Super Jason Scott Presentation 64</b><br />
<a href="http://www.notacon.org/speakers.html#Scott">Jason Scott</a></p>
<p><b>Programming The Sega Genesis For Mad Profit and Crazy Mad Profit</b><br />
<a href="http://www.notacon.org/speakers.html#sigflup">SigFLUP</a></p>
<p><b>Hacking Cognition</b><br />
<a href="http://www.notacon.org/speakers.html#Tottenkoph">Tottenkoph &#038; Selkie</a></p>
<p><b>Intro to Go</b><br />
<a href="http://www.notacon.org/speakers.html#Viers">Jason Viers</a></p>
<p><b>What is Notacon?</b><br />
Notacon is one of the most unique conferences you will ever attend!  Notacon 6 is April 16th &#8211; 19th 2009 held in Cleveland, Ohio.  Notacon explores and showcases technologies, philosophy and creativity often overlooked at many &#8220;hacker cons&#8221;.  <a href="http://www.notacon.org/prereg.html">Registration is open!</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2008/12/notacon-6-speaker-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Maltego 2.01 Released</title>
		<link>http://www.spylogic.net/2008/12/maltego-201-released/</link>
		<comments>http://www.spylogic.net/2008/12/maltego-201-released/#comments</comments>
		<pubDate>Wed, 03 Dec 2008 04:55:36 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[informationgathering]]></category>
		<category><![CDATA[maltego]]></category>
		<category><![CDATA[pentest]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Looks like the fine folks over at Paterva have released version 2.01 of Maltego. If you don&#8217;t know what Maltego is&#8230;look here. Check out some of the changes and new features. From the announcement: Features: * Copy and paste to/from graphs * Copy and paste to/from text * Above can also function as &#8220;import&#8221; * [...]]]></description>
			<content:encoded><![CDATA[<p>Looks like the fine folks over at Paterva have released version 2.01 of Maltego.  If you don&#8217;t know what Maltego is&#8230;<a href="http://spylogic.net/item/366">look here</a>.  Check out some of the changes and new features.  From the <a href="http://www.paterva.com/maltego/download/">announcement</a>:</p>
<p><b>Features:</b></p>
<p>    * Copy and paste to/from graphs<br />
    * Copy and paste to/from text<br />
    * Above can also function as &#8220;import&#8221;<br />
    * Zoom to pointer<br />
    * Looking glass zoom mode<br />
    * Added notch on slider that will return 10,000 entities (if your RAM can stomach it)<br />
    * Brought back &#8220;Run All Transforms&#8221; &#8211; you asked for it!<br />
    * Cancel transform run (e.g. i clicked on the wrong transform and it&#8217;s taking forever while my graph is turning into a green mush, can we please stop this now)<br />
    * Easier Mac install</p>
<p><b>Fixes:</b></p>
<p>    * Authentication proxies now works (including NTLM)<br />
    * Cancel on entity export (small annoying fix)<br />
    * Transform manager window resizes properly (useful for those on E^3s)<br />
    * The dreadful save bug has been fixed (if you never saw it count yourself lucky)</p>
<p>In addition they note the in the upcoming 2.1 version they will be allowing local scriptable transforms!  I am really looking forward to this feature as the custom transform creation process will hopefully get a whole lot easier.</p>
<p>Note that the <a href="http://www.paterva.com/maltego/download/">main download page</a> doesn&#8217;t have the new package yet so if you want it now you need to get the download links from <a href="http://www.paterva.com/forum/index.php/topic,81.0.html">the forum post here</a>.  I would expect the main site updated later today.  </p>
<p>Also&#8230;the crippled &#8220;<a href="http://www.paterva.com/maltego/community-edition/">community edition</a>&#8221; is still on the old version for now (updated shortly I am sure).  By the way, it&#8217;s only $430 USD for the first year, $320 USD per year thereafter for a license of the commercial version&#8230;well worth it!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2008/12/maltego-201-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Young IT Professionals of Northeast Ohio</title>
		<link>http://www.spylogic.net/2008/12/young-it-professionals-of-northeast-ohio/</link>
		<comments>http://www.spylogic.net/2008/12/young-it-professionals-of-northeast-ohio/#comments</comments>
		<pubDate>Mon, 01 Dec 2008 16:27:11 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Cleveland]]></category>
		<category><![CDATA[IT]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[There is a new group forming in Northeast Ohio for IT professionals focused on the younger generation and is an opportunity to network and learn from one another. The first meeting is at the Great Lakes Brewing Company on December 10th @ 6pm (downstairs in the beer cellar). Cost is $15 to help with appetizers [...]]]></description>
			<content:encoded><![CDATA[<p>There is a new group forming in Northeast Ohio for IT professionals focused on the younger generation and is an opportunity to network and learn from one another.  The first meeting is at the <a href="http://www.greatlakesbrewing.com/">Great Lakes Brewing Company</a> on December 10th @ 6pm (downstairs in the beer cellar).  Cost is $15 to help with appetizers but is open bar!  Read: Great Lakes has Christmas Ale on tap!</p>
<p>If you plan on attending please RSVP to Devon Campbell (dcampbell2 [aT] mcpc.com).</p>
<p>This event should be a great way to network and meet others in the area!  Hope to see some of you locals there!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spylogic.net/2008/12/young-it-professionals-of-northeast-ohio/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

